Which Evidence Best Plans an Audit of Untested Data Transfers?

Audit Planning & Systems Testing
Answer Correct answer: D — Reviewing previous system interface testing records provides baseline evidence to assess controls and plan targeted integrity verification steps.

An IS auditor has been asked to review the integrity of data transfer between two business-critical systems that have not been tested since implementation. Which of the following would provide the MOST useful information to plan an audit?

  1. Quality assurance (QA) testing
  2. System change logs
  3. IT testing policies and procedures
  4. Previous system interface testing records Correct Answer

Community Votes

B
67%
D
33%

67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This scenario evaluates whether you prioritize historical testing baselines over operational change tracking when designing an integrity audit.

When critical systems lack recent testing, historical validation data becomes the primary driver for audit scoping. This page clarifies why reviewing past interface tests outweighs monitoring live system changes.

Test-takers often choose system change logs, incorrectly assuming that tracking recent modifications directly validates data transfer integrity compared to examining original test outcomes.

Community Discussion (3 comments)

46080f2 👍 1 Selected: B
Vote against D. could be the indication "...that have not been tested since implementation." There is nothing mentioned about a previous system. Therefore, it is absolutely the first time such data transfers between these system have been executed. So I vote as real human being against all D-votes of AI tools for B.
46080f2 👍 1 Selected: D
The most useful information for an IS auditor to plan an audit of the integrity of data transfer between two business-critical systems would be D. Previous system interface testing records. These records provide insights into how the systems were tested initially, any issues that were identified, and how they were resolved. This historical data is crucial for understanding the current state of the systems and identifying any potential areas of concern.
46080f2 👍 1 Selected: B
System change logs: These logs provide a history of modifications to the systems, which is crucial for understanding potential points of failure or data corruption during transfer15. They reveal when changes were made, what components were affected, and who made the changes. This information helps the auditor focus on areas with higher risk1

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Selecting previous system interface testing records aligns with ISACA’s audit planning framework, which mandates reviewing historical validation evidence before designing new procedures. These records reveal how data flows were originally validated, what error-handling mechanisms existed, and any unresolved defects that require regression testing. By analyzing this baseline, auditors can efficiently allocate resources to high-risk transfer points rather than starting from scratch.

Why the Other Options Are Wrong

Quality assurance testing focuses on pre-deployment development cycles and rarely covers post-implementation interface behavior. System change logs track configuration or code modifications but do not demonstrate whether data integrity controls functioned correctly during those changes. IT testing policies outline procedural requirements across the organization but offer zero system-specific intelligence for scoping this particular audit engagement.

Community Comment Notes

Several learners debated between historical records and change logs, with some arguing that untested systems imply no prior interface exists. As one commenter noted, previous records remain vital because they document the original implementation phase validation. Others emphasized that change logs merely show what was altered, not whether the alterations preserved data accuracy. The consensus highlights that audit planning relies on proven control evidence rather than speculative modification tracking.

Exam Strategy

Always anchor audit planning to existing control evidence before evaluating real-time metrics. When a system lacks recent testing, historical validation records immediately reveal baseline risks and dictate where regression testing should be prioritized.

Frequently Asked Questions

Why aren't change logs better for planning?

Change logs track configuration updates but do not validate whether data integrity controls functioned correctly during those modifications.

How do interface testing records guide audit scope?

They reveal original validation methods, known defect patterns, and residual risks, allowing auditors to prioritize regression testing efforts.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide