Which Evidence Best Plans an Audit of Untested Data Transfers?
An IS auditor has been asked to review the integrity of data transfer between two business-critical systems that have not been tested since implementation. Which of the following would provide the MOST useful information to plan an audit?
Community Votes
67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This scenario evaluates whether you prioritize historical testing baselines over operational change tracking when designing an integrity audit.
When critical systems lack recent testing, historical validation data becomes the primary driver for audit scoping. This page clarifies why reviewing past interface tests outweighs monitoring live system changes.
Test-takers often choose system change logs, incorrectly assuming that tracking recent modifications directly validates data transfer integrity compared to examining original test outcomes.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Selecting previous system interface testing records aligns with ISACA’s audit planning framework, which mandates reviewing historical validation evidence before designing new procedures. These records reveal how data flows were originally validated, what error-handling mechanisms existed, and any unresolved defects that require regression testing. By analyzing this baseline, auditors can efficiently allocate resources to high-risk transfer points rather than starting from scratch.Why the Other Options Are Wrong
Quality assurance testing focuses on pre-deployment development cycles and rarely covers post-implementation interface behavior. System change logs track configuration or code modifications but do not demonstrate whether data integrity controls functioned correctly during those changes. IT testing policies outline procedural requirements across the organization but offer zero system-specific intelligence for scoping this particular audit engagement.Community Comment Notes
Several learners debated between historical records and change logs, with some arguing that untested systems imply no prior interface exists. As one commenter noted, previous records remain vital because they document the original implementation phase validation. Others emphasized that change logs merely show what was altered, not whether the alterations preserved data accuracy. The consensus highlights that audit planning relies on proven control evidence rather than speculative modification tracking.Exam Strategy
Always anchor audit planning to existing control evidence before evaluating real-time metrics. When a system lacks recent testing, historical validation records immediately reveal baseline risks and dictate where regression testing should be prioritized.
Frequently Asked Questions
Why aren't change logs better for planning?
Change logs track configuration updates but do not validate whether data integrity controls functioned correctly during those modifications.
How do interface testing records guide audit scope?
They reveal original validation methods, known defect patterns, and residual risks, allowing auditors to prioritize regression testing efforts.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →