CISA Information System Auditing Process Practice Question
Which TWO of the following are components of audit risk in IS auditing?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detection risk
In IS auditing, audit risk is modeled as the risk that the auditor gives an inappropriate opinion on financial statements that are materially misstated, and its standard components are inherent risk, control risk, and detection risk. Detection risk (A) is correct because it is the risk that the auditor's procedures fail to detect a material misstatement that exists, and it is the component the auditor can directly manage by adjusting the nature, timing, and extent of audit procedures. Inherent risk (D) is correct because it is the susceptibility of an assertion to a material misstatement before considering any related internal controls, arising from factors such as complex IT environments, high transaction volumes, or estimation uncertainty. The other options do not belong: financial risk (B), business risk (C), and operational risk (E) are broader enterprise or management risk categories, not the defined components of the audit risk model used in IS auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Detection risk
Why this is correct
Detection risk is a component of audit risk, representing the risk that audit procedures fail to detect a material misstatement. It combines with inherent and control risk, satisfying the stem's requirement to identify audit risk components in IS auditing.
- ✗
Financial risk
Why it's wrong here
Financial risk is not one of the three components of audit risk (inherent, control and detection risk); it describes exposure to monetary loss, not the probability an auditor issues an inappropriate opinion. It is tempting because IS audits often assess financial exposure, but that belongs to risk assessment of the entity, not the audit risk model itself.
- ✗
Business risk
Why it's wrong here
Business risk concerns threats to an organisation achieving its objectives, not the audit risk model's components of inherent, control and detection risk. It is tempting because auditors do consider business risk when planning engagements, but the question asks specifically for audit risk components, which measure the chance of an incorrect audit opinion.
- ✓
Inherent risk
Why this is correct
Inherent risk is a component of audit risk, representing susceptibility to material misstatement before considering controls. It combines with control and detection risk, satisfying the stem's requirement to identify audit risk components in IS auditing.
- ✗
Operational risk
Why it's wrong here
Audit risk comprises inherent risk, control risk and detection risk; operational risk is a business risk category, not a component of the audit risk model. Operational risk is correctly assessed in enterprise risk management, where it covers losses from failed processes, people or systems.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.