easyMultiple Choice
CISA Practice Question: Has outsourced its IT operations to a third-party…
An organization has outsourced its IT operations to a third-party provider. The IS auditor is planning an audit of the outsourced services. What is the most appropriate source of audit evidence?
⚠ Common exam trap
Watch out — candidates often choose interviews with provider's staff (Option B) because they seem like direct evidence, but they lack the independence and systematic testing that a SOC 2 report provides, which is the gold standard for third-party assurance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service auditor's SOC 2 report
A SOC 2 report (Service Organization Control 2) is specifically designed to provide assurance over a service provider's controls related to security, availability, processing integrity, confidentiality, and privacy. It is issued by an independent service auditor and is the most reliable and relevant source of audit evidence when auditing outsourced IT operations, as it directly addresses the controls in place at the provider.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service provider's financial statements
Why it's wrong here
Financial statements show the provider's solvency, not the control effectiveness the audit needs; they are evidence for vendor viability assessments, not outsourced IT operations. The auditor requires the provider's SOC 2 Type II report or equivalent independent assurance over the control environment.
- ✗
Interviews with provider's staff
Why it's wrong here
Interviews with provider staff yield verbal assertions, which are weak evidence and cannot be independently corroborated without testing. They are tempting because staff hold operational knowledge and are quick to consult, and would be appropriate for gathering context before designing substantive audit procedures.
- ✓
Service auditor's SOC 2 report
Why this is correct
A SOC 2 report, produced by the service provider's independent auditor, gives the IS auditor evidence on the design and operating effectiveness of controls at the outsourced provider. It directly addresses the third-party control environment that the organisation cannot test itself.
- ✗
Internal audit reports from the provider
Why it's wrong here
Provider internal audit reports are produced under the provider's own scope and controls, so they give indirect evidence rather than the auditor's independent testing of the outsourced services. They are tempting because they are readily available and cheap, and would support a review of the provider's control environment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.