hardMultiple Choice
CISA Practice Question: The IT audit manager for a multinational…
You are the IT audit manager for a multinational corporation. The company recently implemented a new enterprise resource planning (ERP) system using a phased rollout approach. The first phase (finance module) was deployed to three regional offices six months ago. During a post-implementation review, you discovered that the user acceptance testing (UAT) for the finance module was completed in only two days instead of the planned two weeks. The UAT was performed by a small group of power users selected by the project manager, and they reported no critical issues. However, after go-live, several finance staff in one region found that the system does not support a statutory reporting requirement specific to that country, which was not tested. The project manager argues that the requirement was never documented in the business requirements specification. The system has been live for six months, and the missing functionality requires a significant customization that will take three months and cost $200,000. Management is reluctant to fund the customization because the budget is exhausted. As the IT auditor, what is the BEST course of action?
⚠ Common exam trap
The trap here is that candidates focus on the missing requirement or blame the project manager, rather than recognizing that the core issue is a weak UAT process that failed to include all regional stakeholders and statutory requirements, which is a systemic control weakness the auditor should address.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Recommend that management implement a formal UAT process with representatives from all regions and include a checklist of statutory requirements for future rollouts
The root cause is a deficient UAT process, not just a missing requirement. A formal UAT process with representatives from all regions and a statutory requirements checklist would have caught the country-specific reporting need before go-live. As an IT auditor, recommending process improvements for future rollouts addresses the systemic control weakness, which is more effective than blaming individuals or accepting risk without remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Report the project manager to senior management for failing to include the requirement
Why it's wrong here
Escalating the project manager addresses individual blame, not the control weakness that allowed an undocumented statutory requirement to escape UAT. Auditors report process failures and their business impact to management, not personnel conduct. This action would fit a proven fraud or deliberate policy breach, which the stem does not evidence.
- ✗
Recommend that the organization accept the risk and proceed without the customization
Why it's wrong here
Accepting the risk leaves a known statutory reporting gap unfunded and unmitigated, which the auditor cannot endorse because compliance exposure and financial misstatement remain unaddressed. Risk acceptance is a valid management response only after the exposure is quantified, formally approved by the accountable owner and recorded in the risk register with a monitoring plan — not used to close an audit finding of missing regulatory functionality.
- ✗
Advise the project manager to retroactively document the requirement and request a change order for the customization
Why it's wrong here
Retroactive documentation and a change order legitimise the omission after go-live without addressing why UAT was compressed and scoped to power users, leaving the control gap intact for later phases. Change orders suit approved scope changes, not requirements missed because testing failed to involve affected regional finance staff.
- ✓
Recommend that management implement a formal UAT process with representatives from all regions and include a checklist of statutory requirements for future rollouts
Why this is correct
The two-day UAT by hand-picked power users missed a country-specific statutory requirement, so the control weakness is the UAT design itself. Recommending a formal process covering all regions with a statutory-requirement checklist addresses the root cause and prevents recurrence in later phased rollouts.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.