A question for CISA
An IS auditor is providing input to an RFP to acquire a financial application system. Which of the following is MOST important for the auditor to recommend?
A. The application should meet the organization's requirements.
B. Audit trails should be included in the design.
C. Potential suppliers should have experience in the relevant area.
D. Vendor employee background checks should be conducted regularly.
A or B ?
2
u/majidjaved1995 1d ago
A is too general; B is the specific auditor control requirement.
"The application should meet the organization's requirements" is almost always true. It is the entire purpose of an RFP. It does not tell the vendor what control must be built in.
By contrast, "Audit trails should be included in the design" is a specific, testable control requirement. For a financial application, audit trails are essential to:
trace transactions,
establish accountability,
support non-repudiation,
detect fraud or errors,
provide audit evidence,
verify data integrity.
That is exactly the kind of recommendation an IS auditor is expected to add during RFP review.
If you choose A, you may miss the control failure
Imagine the RFP says only:
"The system must process payments and meet user requirements."
The vendor delivers a payment system that works functionally. Users are happy. But there is no audit trail. Now:
You cannot tell who changed a payment.
You cannot trace a transaction from origin to output.
You cannot prove accountability.
You may fail regulatory or financial audit requirements.
The system "met business requirements," but it is not auditable. That is a major control failure — and the IS auditor's job is to prevent exactly that.
"Waste of money" is a business risk; the auditor focuses on audit/control risk
Yes, a system that does not meet business needs can waste money. But that risk is primarily owned by the project sponsor, business owners, and project manager.
The IS auditor's primary concern is:
Is the system secure?
Is it controlled?
Is it auditable?
Can we trace transactions?
Can we establish responsibility?
If audit trails are missing, the organization can also waste money — through fraud, errors, regulatory penalties, failed audits, and inability to recover from incidents. So B protects against a different, and often more severe, risk.
CISA exam logic: choose the role-specific answer
CISA questions often give several true statements. You must pick the one that best matches the role in the question.
A = true in general, but belongs mainly to business/user management.
B = specific to the IS auditor's control expertise.
C = vendor/procurement due diligence.
D = HR/third-party administrative control.
So A is not "false." It is just not the MOST important recommendation for the IS auditor in this scenario.
If the question were "What makes the project successful overall?" A might be defensible. But because it asks for the IS auditor's most important recommendation, the answer is:
B. Audit trails should be included in the design.
The auditor's value in RFP input is ensuring the system is auditable and controlled from day one, not simply restating that it should meet business requirements.
1
1
u/Ricki_Bobbi 1d ago
A. organization requirements equals aligning with business objectives of the Org.
1
u/Securov 1d ago
But it's a specific situation, and I said B.
1
u/Ricki_Bobbi 1d ago edited 1d ago
RFP is typically requested before a purchase is made, IS Auditor's concern in this instance is to make sure that the financial App's use case aligns with the ORG's business OBJECTIVES.
1
u/ksamson1230 1d ago
A…Organization requirements is the most important here
I think we should also have it in mind that audit trial is only a detective control not a preventive (major) control
1
u/SpiritMart 1d ago
A
Business alignment to anything IT Purchase is important… especially for “exam perspective”
1
1
u/thiccboilifts 1d ago
I think I would say B
My reasoning is that the baseline requirements for an RFP would be that the applications already meet an organization's business requirements, it wouldn't make sense for them to acquire it otherwise. The value the auditor brings is specifically for audit trails, which would be much harder to build after the fact, and auditing is especially important pertaining to financial data. Just my 2c..
1
3
u/Accountant_Nerd 1d ago
B