CISA Information System Auditing Process Practice Question
During the follow-up phase of an audit, the auditor discovers that a previous finding has not been remediated. What is the auditor's BEST course of action?
⚠ Common exam trap
CISA often tests the boundary between the auditor's role and management's role — candidates incorrectly pick 'close as accepted risk' or 're-test' when the correct answer is always to escalate unresolved findings to those with authority to accept the risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the lack of remediation to senior management
When a previously reported finding remains unremediated after the agreed follow-up period, the auditor's responsibility shifts from re-testing to escalation. ISACA audit standards require that unresolved findings be reported to senior management (and ultimately the board/audit committee) so that those with authority to accept risk or allocate resources are formally made aware. Reporting the lack of remediation preserves the audit trail and forces a documented management decision (remediate, accept, or mitigate).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform additional testing to confirm the finding
Why it's wrong here
Additional testing confirms whether the original condition still exists, but the auditor already established non-remediation during follow-up. Re-testing repeats work without advancing resolution; this approach suits validating a disputed or ambiguous finding, not one already verified as outstanding and needing escalation.
- ✓
Report the lack of remediation to senior management
Why this is correct
Unresolved findings represent unmitigated risk that the auditor cannot accept or remediate. Escalating to senior management, who own risk acceptance and resource allocation, ensures the issue receives the authority needed to compel action, satisfying the follow-up requirement to verify remediation status.
- ✗
Ignore the finding since it was previously reported
Why it's wrong here
Ignoring a finding because it was reported previously abandons the auditor's follow-up obligation; unresolved findings must be escalated to management and the audit committee. Disregarding prior findings would suit nothing in audit practise, as reporting creates a duty to track remediation until closure.
- ✗
Close the finding as accepted risk
Why it's wrong here
Accepting risk is a management decision, and an auditor cannot unilaterally close a finding or transfer ownership of the risk. Closing as accepted risk applies only once management formally documents acceptance and the audit committee endorses it; here the finding remains open and requires escalation.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.