Courseiva

CISA Information System Auditing Process Practice Question

Which of the following audit types is most likely to be conducted by an employee of the organization being audited, potentially raising independence concerns?

⚠ Common exam trap

CISA often tests the confusion between audit type (IS, compliance, financial) and audit relationship (internal vs. external), so candidates who focus on the word 'audit' rather than 'employee of the organization' pick the wrong option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Internal audit

An internal audit is performed by auditors who are employees of the organization being audited. Because they report within the same organizational structure they are reviewing, their objectivity and independence can be impaired by management pressure, familiarity, or career incentives. This inherent independence concern is why ISACA emphasizes that internal auditors must maintain objectivity and why external audits are often used for higher-assurance opinions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IS audit

    Why it's wrong here

    An IS audit examines controls over information systems and can be performed by internal staff, external firms or specialists; the label describes scope, not the auditor's employer. It attracts selection because IS audits are frequently staffed internally, but the independence issue arises from being an employee, which applies to any audit type.

  • ✓

    Internal audit

    Why this is correct

    Internal audit is performed by employees of the same organisation, so the auditor reports through internal management and may lack freedom from the activities being reviewed. That structural reporting relationship creates the independence concern the stem describes, unlike external audit or third-party assessments conducted by parties outside the entity.

  • ✗

    Compliance audit

    Why it's wrong here

    A compliance audit tests adherence to regulations, policies or standards, and its subject matter does not determine who performs it; an internal auditor could equally conduct an IS or operational audit. It is tempting because compliance work is often delegated in-house, yet independence concerns stem from the auditor's employment relationship, not the audit category.

  • ✗

    External audit

    Why it's wrong here

    An external audit is by definition conducted by an independent party outside the organisation, typically a public accounting or audit firm, so it removes rather than raises the independence concern. It is tempting because external audits are the recognised assurance mechanism, but the stem asks which type an employee of the audited organisation would perform.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.