Audit Planning & Methodology Flashcards
7 cards from real ITA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Audit Planning & Methodology flashcards as text
Which IT audit standard or framework is most commonly used by IT auditors to structure their work?
Answer: ISACA's ITAF (IT Assurance Framework)
ISACA's ITAF provides a comprehensive framework of standards, guidelines, and tools specifically designed for IT assurance and audit professionals.
What is the role of an 'audit universe' in IT audit planning?
Answer: It is a comprehensive inventory of all auditable entities, systems, and processes within the organization
The audit universe is a complete catalog of all auditable areas that forms the basis for risk-based prioritization and multi-year audit planning.
In IT audit methodology, what is the purpose of establishing 'audit criteria'?
Answer: To define the standards or benchmarks against which audit evidence will be evaluated
Audit criteria provide the standards, policies, or benchmarks that the auditor uses to measure and evaluate the adequacy of controls and practices identified during the audit.
Which concept describes combining multiple types of audit procedures to reduce overall audit risk?
Answer: Audit triangulation
Audit triangulation uses multiple sources of evidence and types of procedures to corroborate findings and reduce the risk that any single procedure will miss an issue.
What should an IT auditor do if the scope of an audit needs to change after the engagement has begun?
Answer: Formally document and communicate the scope change to management and obtain approval
Any scope change must be formally documented and approved by appropriate management to maintain audit integrity, accountability, and proper governance over the engagement.
Why is an 'entrance conference' conducted at the start of an IT audit fieldwork phase?
Answer: To formally introduce the audit team, confirm scope, logistics, and set expectations with the auditee
The entrance conference aligns the audit team and auditee on the audit objectives, scope, schedule, and information-gathering process before fieldwork begins.
In IT audit planning, 'inherent risk' refers to:
Answer: The risk that exists in an IT environment before any controls are applied
Inherent risk is the level of risk that exists in a process or system due to its nature, complexity, or environment, absent any mitigating controls.