CISA Information System Auditing Process Practice Question
During a follow-up audit, an IS auditor finds that management implemented a compensating control rather than the recommended primary control to address a previously reported high-risk finding. The residual risk is now within the organization's risk appetite. How should the IS auditor respond?
⚠ Common exam trap
The trap here is treating the original recommendation as a binding requirement, when in fact management may satisfy the underlying risk reduction through an alternative compensating control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evaluate whether the compensating control adequately mitigates the risk and close the finding if it does.
Audit recommendations describe a desired risk outcome, not a mandatory control design. When management implements a compensating control that reduces residual risk to within the organization's risk appetite, the auditor should evaluate whether that control adequately mitigates the risk and close the finding if it does. Reopening, escalating, or mislabeling the response as risk acceptance would misrepresent the outcome and ignore management's ownership of risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Evaluate whether the compensating control adequately mitigates the risk and close the finding if it does.
Why this is correct
The auditor's responsibility is to assess whether the implemented control reduces risk to an acceptable level, regardless of whether it matches the original recommendation. If the compensating control adequately mitigates the risk and residual risk falls within the risk appetite, the finding can be closed. This reflects the principle that management owns risk response while the auditor provides objective assurance on the outcome.
- ✗
Escalate the matter to the audit committee because a compensating control was used.
Why it's wrong here
Escalation is unwarranted when residual risk has been reduced to within the organization's risk appetite. Using a compensating control is a legitimate risk response when it effectively addresses the underlying risk. Escalating simply because the implementation differed from the recommendation would misrepresent the situation and could damage the auditor's credibility. Escalation is reserved for unresolved high-risk issues or management's failure to act.
- ✗
Document that management accepted the risk without implementing the recommended control.
Why it's wrong here
This mischaracterizes the situation. Management did not simply accept the risk; it implemented a compensating control that brought residual risk within appetite. Documenting it as risk acceptance would inaccurately portray management's action and could mislead the audit committee. The auditor should evaluate the effectiveness of the compensating control and document that assessment, not frame a valid risk response as inaction.
- ✗
Reopen the original finding because the recommended control was not implemented as specified.
Why it's wrong here
Reopening the finding is inappropriate because the objective of the recommendation was to reduce risk to an acceptable level, which has been achieved. Recommendations are not prescriptive mandates; management may select alternative controls that address the risk. The auditor's role is to evaluate whether the risk is mitigated, not to insist on a specific control design. Reopening would undermine management's ownership of risk responses.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.