Courseiva

CISA Information System Auditing Process Practice Question

During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. Which of the following actions should the auditor prioritize?

⚠ Common exam trap

CISA often tests the misconception that new systems should be excluded or delayed from audit until 'stable' — candidates forget that high inherent risk demands earlier, not later, audit attention.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Include a review of the ERP system in the audit scope due to the high inherent risk

A newly implemented ERP system represents high inherent risk due to its complexity, cost, and impact on financial reporting and operations, so the auditor should include it in the audit scope. Prioritizing the ERP review ensures that risks introduced by the new system — such as data migration errors, access control gaps, and process changes — are assessed early. Excluding or delaying the audit would leave significant risk unaddressed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Exclude the ERP system from the audit scope because it is new and not yet stable

    Why it's wrong here

    Excluding the ERP system removes from scope the very area of highest risk, since a recent implementation carries elevated risk of control gaps and data migration errors. It is tempting because newly deployed systems may still be settling, and deferring detailed testing can be justified where instability would prevent meaningful evidence gathering.

  • ✓

    Include a review of the ERP system in the audit scope due to the high inherent risk

    Why this is correct

    A newly implemented ERP system carries high inherent risk because of untested configuration, data migration and access provisioning. Including it in the audit scope ensures the auditor evaluates these risks during planning, directing resources toward the area most likely to contain material weaknesses.

  • ✗

    Delay the audit until the ERP system has been fully stabilized for six months

    Why it's wrong here

    Delaying the audit leaves the newly implemented ERP system's risks unassessed during the period of greatest exposure, contrary to prioritising risk-based planning. It is tempting because waiting for stabilisation can improve evidence quality, and would be reasonable where the system is genuinely too volatile to test meaningfully.

  • ✗

    Focus only on financial reporting controls related to the ERP system

    Why it's wrong here

    Restricting scope to financial reporting controls ignores the ERP system's wider risk profile, including operational, compliance and access controls that a new implementation exposes. It is tempting because financial reporting is often the auditor's primary concern, and would be the right focus for a narrowly scoped financial statement audit rather than an IS audit.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.