easyMultiple Select
CISA Practice Question: Which TWO of the following are primary objectives…
Which TWO of the following are primary objectives of the audit planning phase? (Select TWO.)
⚠ Common exam trap
Test-takers frequently confuse the planning phase with the execution phase, leading candidates to select 'develop detailed audit procedures' (Option A) as a planning objective, when it is actually a step in the audit program development after planning is complete.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify and assess risks relevant to the audit
Option B is correct because identifying and assessing risks relevant to the audit is a core purpose of audit planning; planning determines which areas are risky and therefore where audit effort should be focused, consistent with risk-based auditing standards. Option E is correct because defining the audit scope and objectives establishes what the audit will cover, its boundaries, and what it is intended to achieve, which is a fundamental planning activity that guides all subsequent work. Option A is not a primary planning objective because developing detailed audit procedures typically occurs after planning, during the design/programming stage, once scope, objectives, and risks are understood. Option C is not a planning objective because testing the effectiveness of internal controls is an execution/fieldwork activity, not something accomplished during planning. Option D is not a planning objective because issuing the final audit report is the concluding/reporting phase, which occurs after fieldwork and evidence evaluation are complete.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Develop detailed audit procedures
Why it's wrong here
Detailed audit procedures are developed during fieldwork execution, after planning has fixed scope, objectives and criteria. It is tempting because procedure design feels preparatory, yet planning's objectives are defining scope, understanding the entity and assessing risk to build the audit programme.
- ✓
Identify and assess risks relevant to the audit
Why this is correct
Audit planning determines scope, objectives and the risks that could cause material misstatement, so identifying and assessing relevant risks is a primary objective. This scoping of risk directs the nature, timing and extent of subsequent audit procedures.
- ✗
Test the effectiveness of internal controls
Why it's wrong here
Testing control effectiveness occurs during fieldwork, when evidence is gathered and evaluated. It is tempting because controls dominate audit work, but planning instead defines objectives, scope, criteria and resource requirements. Control testing is an execution activity, not a planning objective.
- ✗
Issue the final audit report
Why it's wrong here
Issuing the final report happens at the reporting stage, after fieldwork and review are complete. It is tempting because the report is the visible audit output, but planning instead establishes objectives, scope, criteria and resourcing. Reporting is a separate phase, not a planning objective.
- ✓
Define audit scope and objectives
Why this is correct
Defining scope and objectives is a primary objective of audit planning: it establishes the boundaries, resources and criteria the engagement will address, ensuring the audit is directed at the relevant risks before fieldwork begins. Without this, subsequent testing lacks a baseline against which evidence is assessed.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.