Reporting Irregularities to External Authorities

IS Audit Process
Answer Correct answer: A — Obtain approval from audit management to submit the report.

An IS auditor finds that irregularities have occurred and that auditee management has chosen to ignore them. If reporting to external authorities is required, which of the following is the BEST action for the IS auditor to take?

  1. Obtain approval from audit management to submit the report. Correct Answer
  2. Obtain approval from auditee management to release the report.
  3. Obtain approval from both audit and auditee management to release the report.
  4. Submit the report to appropriate regulators immediately.

Community Votes

A
75%
D
25%

75% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This tests the auditor's reporting hierarchy and independence; the trap is believing the auditor acts alone or needs the auditee's permission to report non-compliance.

When auditee management ignores irregularities requiring external reporting, the auditor must escalate to audit management to ensure compliance without auditee interference.

Choosing options B or C is incorrect because the auditor should never ask the auditee (who is ignoring the issue) for permission to report them.

Community Discussion (4 comments)

Swallows 👍 1 Selected: D
If wrongdoing occurs and is ignored by auditee management, they are legally and ethically responsible to report it. They are expected to report such serious issues to regulators as soon as possible. Auditors have a duty to act independently and to report the truth. They are expected to report issues immediately, without seeking approval from auditees or management.
Sibsankar 👍 1
Sorry for the earlier response in C. The accurate answer will be D
marc4354345 👍 3 Selected: A
If reporting to external authorities is required then the auditee must not be able to block reporting.
Sibsankar 👍 1
It will be C The BEST action for the IS auditor, when irregularities are found and reporting to external authorities is required, is to obtain approval from both audit and auditee management to release the report. This approach ensures that there is a consensus and understanding between the audit team and the auditee management before taking any action. It helps maintain transparency and allows for a coordinated response.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

ISACA standards dictate that the auditor reports to senior management or the audit committee. When external reporting is mandated, the auditor must get authorization from their own chain (audit management) to proceed, ensuring the report is accurate and the process is sound.

Why the Other Options Are Wrong

Options B and C involve asking the auditee for approval, which creates a conflict of interest since they are ignoring the issue. Option D suggests acting immediately without internal verification, which bypasses standard audit governance protocols unless specific laws dictate otherwise.

Community Comment Notes

Comment [1] correctly identifies that the auditee must not block reporting. Comment [2] argues for immediate reporting (D), but exam protocols usually prioritize the internal audit chain of command to validate the finding before external release.

Official Reference

Exam Strategy

Always look for the option that maintains auditor independence and follows the reporting hierarchy. Never select an option that gives the auditee veto power over external reporting of significant irregularities.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide