Courseiva

CISA Information System Auditing Process Practice Question

Which TWO of the following are phases of the audit process? (Select two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Planning

Option B, Planning, is correct because planning is the foundational phase of the audit process, where the auditor defines the audit scope, objectives, criteria, and methodology before fieldwork begins. Option E, Reporting, is correct because reporting is the concluding phase in which the auditor documents findings, conclusions, and recommendations in the audit report for management and stakeholders. The audit process is commonly structured as planning, fieldwork/execution, and reporting, so these two options align with the recognized phase model. Option A, Budgeting, is not a distinct audit phase; budgeting is a management activity that may support planning but is not itself a phase. Option C, Risk assessment, is a technique or activity performed within the audit process (particularly during planning and fieldwork) rather than a standalone phase. Option D, Training, is an administrative or professional-development activity and is not one of the phases of the audit process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Budgeting

    Why it's wrong here

    Budgeting is an administrative finance activity supporting the audit function, not a phase of the audit process itself. It is tempting because resourcing and cost planning accompany engagements, but the recognised phases are planning, fieldwork, reporting and follow-up.

  • ✓

    Planning

    Why this is correct

    Planning is the initial audit phase, where scope, objectives, risk assessment and resource allocation are defined before evidence gathering begins. This satisfies the stem's requirement for a genuine audit process phase, establishing the foundation for subsequent fieldwork and reporting activities.

  • ✗

    Risk assessment

    Why it's wrong here

    Risk assessment is a planning activity that informs the audit, not one of the process phases such as planning, fieldwork, reporting and follow-up. It is tempting because assessing risk underpins scoping decisions, yet the exam expects the sequential engagement phases instead.

  • ✗

    Training

    Why it's wrong here

    Training develops auditor competence and is not a phase of the audit process; phases are planning, fieldwork, reporting and follow-up. It is tempting because ongoing training supports audit quality, but it sits outside the engagement lifecycle the question asks about.

  • ✓

    Reporting

    Why this is correct

    Reporting is the concluding audit phase, where findings, conclusions and recommendations are communicated to management. This satisfies the stem's requirement for a genuine audit process phase, following planning and fieldwork, and formally documenting results for stakeholders.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.