Courseiva

CISA Information System Auditing Process Practice Question

What is the primary purpose of the planning phase in an IS audit?

⚠ Common exam trap

CISA often tests the sequence of audit phases, and candidates may confuse planning with fieldwork by selecting 'execute audit tests' or with reporting by selecting 'issue the final report' when asked about the primary purpose of planning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To identify risks and define audit scope

The planning phase of an IS audit is where the auditor defines the audit objectives, identifies and assesses risks, determines the scope and criteria, and develops the audit program. This foundational phase ensures that the audit is focused on the areas of greatest risk and that resources are allocated effectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To execute audit tests

    Why it's wrong here

    Executing audit tests belongs to the fieldwork or execution phase; planning instead defines scope, objectives, risk and resource allocation. It is tempting because testing is the visible audit activity, and would be correct if the question asked which phase gathers and evaluates evidence against controls.

  • ✗

    To issue the final report

    Why it's wrong here

    Issuing the final report belongs to the reporting phase, which follows fieldwork and evidence gathering; planning instead defines audit objectives, scope, criteria and resource allocation. It is tempting because the report is the audit's visible deliverable, and planning does shape its eventual content, but the report itself is produced only after testing concludes.

  • ✓

    To identify risks and define audit scope

    Why this is correct

    The planning phase establishes the audit's foundation by assessing inherent and control risks, then using that risk assessment to define scope, objectives, criteria and resource allocation, ensuring fieldwork concentrates effort on the areas of greatest significance to the organisation.

  • ✗

    To follow up on findings

    Why it's wrong here

    Following up on findings occurs during reporting and post-audit monitoring, not planning, so it cannot be the planning phase's primary purpose. It is tempting because remediation tracking is a recognised audit activity, and would be the right answer for a question about the purpose of audit follow-up procedures.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.