mediumMultiple Select
CISA Practice Question: Which THREE of the following are acceptable…
Which THREE of the following are acceptable methods for gathering audit evidence? (Select THREE.)
⚠ Common exam trap
The trap here is that candidates may mistakenly believe that inquiry alone (Option D) is insufficient, but inquiry is a valid evidence-gathering method when combined with other procedures, while accepting unsupported assertions (Option A) and hearsay (Option E) are never acceptable as primary evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Observation of processes being performed
Observation of processes being performed (B) is a valid evidence-gathering method because the auditor directly witnesses controls or procedures in operation, providing first-hand evidence of how activities are actually carried out. Reperformance of control procedures (C) is acceptable because the auditor independently executes the control or procedure and compares the result to the original, yielding highly reliable evidence of operating effectiveness. Inquiry of personnel (D) is an accepted method, as auditors routinely obtain written or oral information from knowledgeable staff, though it is typically corroborated with other evidence due to its lower reliability. Accepting management's assertions without corroboration (A) is not acceptable because assertions alone are not sufficient, appropriate audit evidence and must be verified. Obtaining hearsay from third parties (E) is not acceptable because unverified second-hand information lacks the reliability and directness required for audit evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accepting management's assertions without corroboration
Why it's wrong here
Management assertions alone provide no independent verification, so they cannot support an audit conclusion; evidence must be corroborated through inspection, observation, recalculation or confirmation. It tempts because management representations are a required, formal part of an audit, but only as a supplement to other evidence, never as its substitute.
- ✓
Observation of processes being performed
Why this is correct
Observation involves watching personnel perform a process or control in real time, providing direct evidence that the procedure exists and is executed as described. It is an accepted evidence-gathering technique, though it only reflects performance at the moment of observation rather than the whole period.
- ✓
Reperformance of control procedures
Why this is correct
Reperformance means the auditor independently executes the control or procedure, such as recalculating a total or re-running a validation check, and compares the result with the organisation's output. It yields strong evidence because the auditor directly verifies the control operates as intended.
- ✓
Inquiry of personnel
Why this is correct
Inquiry involves interviewing personnel to obtain information or explanations about processes and controls. It is an accepted evidence-gathering method, but because responses are subjective and unverified, it should be corroborated with inspection, observation or reperformance before conclusions are drawn.
- ✗
Obtaining hearsay from third parties
Why it's wrong here
Hearsay is uncorroborated second-hand testimony, so it lacks the reliability and verifiability audit evidence requires; auditors must trace claims to source records or direct observation. It tempts because interviews and third-party enquiries are legitimate evidence-gathering techniques, but only when the information obtained is independently substantiated.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.