hardMultiple ChoiceObjective-mapped
CISA Practice Question: During a systems audit, the auditor finds that…
During a systems audit, the auditor finds that the project did not follow the organization's systems development methodology. What should the auditor do FIRST?
⚠ Common exam trap
Watch out — candidates often confuse the auditor's investigative curiosity (interviewing the team) with the required procedural first step (reporting and assessing control impact), leading them to select Option D instead of the correct audit response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the deviation and assess the impact on controls
The auditor's first responsibility upon discovering a deviation from the organization's systems development methodology is to report the finding and assess the impact on internal controls. This aligns with ISACA's audit standards, which require auditors to evaluate whether the deviation introduces risks to data integrity, security, or project governance. Without this assessment, the auditor cannot determine the severity of the non-compliance or recommend appropriate corrective actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept if the project is on schedule
Why it's wrong here
Deviation from methodology must be addressed regardless of schedule.
- ✗
Recommend that the project be stopped
Why it's wrong here
Stopping is not the first action; impact assessment is needed.
- ✓
Report the deviation and assess the impact on controls
Why this is correct
The auditor must report and evaluate the risk.
- ✗
Interview the project team to understand why
Why it's wrong here
Interviewing is part of assessment but reporting is the initial step.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.