CISA Information System Auditing Process Practice Question
Which of the following is a permanent file item in an IS audit working paper?
⚠ Common exam trap
CISA often tests the distinction between permanent and current audit files, and candidates frequently misclassify engagement-specific evidence like audit programs or findings as permanent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Organizational chart of the IT department
The organizational chart of the IT department is a permanent file item because it documents the entity's structure and is retained across multiple audit engagements. Permanent files contain information of continuing relevance, such as organizational charts, accounting manuals, and long-term contracts. Current year's audit program and findings are current file items, and confirmation letters are also current file evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Confirmation letters from vendors
Why it's wrong here
Vendor confirmation letters evidence balances for one audit period, so they belong in the current file rather than the permanent file, which retains continuing items such as contracts and organisational charts. They are tempting because confirmations are externally sourced and often retained, but their relevance expires with the engagement.
- ✗
Current year's audit program
Why it's wrong here
The current year's audit programme is prepared for and consumed by this engagement, so it is filed in the current working papers, not the permanent file, which holds continuing reference material. It is tempting because programmes guide recurring audits, yet each year's version is superseded once the audit concludes.
- ✓
Organizational chart of the IT department
Why this is correct
Permanent files hold enduring reference material relevant across multiple audits, such as organisational charts, policies and system inventories. An IT department organisational chart retains ongoing relevance to governance and segregation-of-duties assessments, unlike current-year working papers that are superseded each engagement.
- ✗
List of audit findings for the current year
Why it's wrong here
Findings from the current year relate only to this audit and are superseded by the next engagement's results, so they belong in the current file. They are tempting because findings inform future planning, but the permanent file holds continuing items such as charters and long-term agreements.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.