CISA Information System Auditing Process Practice Question
Which TWO of the following are phases of the audit process? (Select two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Planning
Option B, Planning, is correct because planning is the foundational phase of the audit process, where the auditor defines the audit scope, objectives, criteria, and methodology before fieldwork begins. Option E, Reporting, is correct because reporting is the concluding phase in which the auditor documents findings, conclusions, and recommendations in the audit report for management and stakeholders. The audit process is commonly structured as planning, fieldwork/execution, and reporting, so these two options align with the recognized phase model. Option A, Budgeting, is not a distinct audit phase; budgeting is a management activity that may support planning but is not itself a phase. Option C, Risk assessment, is a technique or activity performed within the audit process (particularly during planning and fieldwork) rather than a standalone phase. Option D, Training, is an administrative or professional-development activity and is not one of the phases of the audit process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Budgeting
Why it's wrong here
Budgeting is an administrative finance activity supporting the audit function, not a phase of the audit process itself. It is tempting because resourcing and cost planning accompany engagements, but the recognised phases are planning, fieldwork, reporting and follow-up.
- ✓
Planning
Why this is correct
Planning is the initial audit phase, where scope, objectives, risk assessment and resource allocation are defined before evidence gathering begins. This satisfies the stem's requirement for a genuine audit process phase, establishing the foundation for subsequent fieldwork and reporting activities.
- ✗
Risk assessment
Why it's wrong here
Risk assessment is a planning activity that informs the audit, not one of the process phases such as planning, fieldwork, reporting and follow-up. It is tempting because assessing risk underpins scoping decisions, yet the exam expects the sequential engagement phases instead.
- ✗
Training
Why it's wrong here
Training develops auditor competence and is not a phase of the audit process; phases are planning, fieldwork, reporting and follow-up. It is tempting because ongoing training supports audit quality, but it sits outside the engagement lifecycle the question asks about.
- ✓
Reporting
Why this is correct
Reporting is the concluding audit phase, where findings, conclusions and recommendations are communicated to management. This satisfies the stem's requirement for a genuine audit process phase, following planning and fieldwork, and formally documenting results for stakeholders.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.