CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An organization is implementing an enterprise resource planning (ERP) system. The project team plans to migrate legacy data without performing a full reconciliation between source and target systems. As an IS auditor, which of the following should be your PRIMARY concern?
⚠ Common exam trap
CISA often tests the auditor's ability to distinguish primary data integrity risks from secondary project risks (schedule, decommissioning); candidates pick timeline or UAT concerns because they sound plausible but miss the core data quality issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incomplete or inaccurate data may be loaded into the new system
The primary audit concern when legacy data is migrated without full reconciliation is that incomplete or inaccurate data will be loaded into the new ERP, leading to corrupted financial records, faulty reporting, and loss of data integrity. Reconciliation between source and target is a fundamental data migration control that detects missing, duplicated, or transformed records. Without it, the organization cannot assert data completeness or accuracy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The legacy system may be decommissioned prematurely
Why it's wrong here
Premature decommissioning affects availability and rollback capability, but it is a consequence of migration decisions rather than the direct effect of skipping reconciliation. Unreconciled data leaves completeness and accuracy unverified, which is the audit risk. Decommissioning timing would be primary only where legacy retention is the specific control under review.
- ✗
User acceptance testing may be delayed
Why it's wrong here
Delayed user acceptance testing is a schedule consequence, not a data integrity risk. Skipping reconciliation means unverified completeness and accuracy of migrated records, which can corrupt financial reporting and controls. UAT timing would be the primary concern only where testing itself is the control being assessed, not data accuracy.
- ✗
The data migration may exceed the planned timeline
Why it's wrong here
Timeline overrun is a project management concern, not an audit assurance issue. Without reconciliation, the completeness and accuracy of migrated data cannot be verified, risking materially incorrect ERP records. Schedule slippage would be the primary concern only when the audit objective is delivery performance rather than data integrity.
- ✓
Incomplete or inaccurate data may be loaded into the new system
Why this is correct
Skipping full reconciliation removes the control that detects records lost, duplicated or corrupted during migration. Without it, incomplete or inaccurate data enters the ERP and may drive incorrect transactions and reporting, making data integrity the auditor's primary concern.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.