Next Step When Periodic Access Reviews Are Missing | CISA

Access Control & Audit Procedures
Answer Correct answer: D — Verify management's approval for this exemption before documenting the finding or escalating to senior leadership.

An IS auditor finds that periodic reviews of read-only users for a reporting system are not being performed. Which of the following should be the IS auditor's NEXT course of action?

  1. Obtain a verbal confirmation from IT for this exemption
  2. Review the list of end users and evaluate for authorization.
  3. Report this control process weakness to senior management.
  4. Verify management's approval for this exemption. Correct Answer

Community Votes

D
50%
B
50%

50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the audit principle of validating authorized exceptions before escalating deficiencies, with the common trap being premature reporting or jumping to granular user data checks.

When an IS auditor discovers unperformed periodic access reviews, verifying documented management approval for an exemption is the required next step. CISA methodology prioritizes investigation over immediate escalation to prevent false positives.

Option B is frequently selected because auditors instinctively want to validate individual accounts, but this ignores the procedural context and potential authorized management exemptions.

Community Discussion (7 comments)

blehbleh 👍 1 Selected: C
This is C. No where in the question does it state they have an exemption for this, it just isn't happening. If it should be happening and it isn't what do you do. You take it to management to notify them.
PurpleParrot 👍 1 Selected: D
I believe since it is already a control weakness, the best option seems D to identify for exemption in the policy before reporting.
RS66 👍 1 Selected: B
D is wrong. Management is not allowed to approve exemptions, senior management is. The answer is B.
4dfe785 👍 1 Selected: B
Yes the auditor can verify with management but first review the list of users and their access to have a batter understanding of the situation. I think approval from management should be after performing B.
46080f2 👍 2 Selected: B
The classification of data based on access authorizations is the responsibility of the data owner. So the next step is to first check this regular process, i.e. A. Additional involvement of the management of the organizational structure may or may not have been defined by the data owner when defining the authorization process in coordination with the security officer. I therefore rule out D. as the next step.
Swallows 👍 1 Selected: D
Before escalating the issue to senior management, it's essential for the IS auditor to confirm whether there's a valid reason for the exemption from periodic reviews of read-only users. Management's approval is necessary to ensure that the exemption is authorized and documented appropriately. By verifying management's approval, the auditor can understand the rationale behind the exemption and assess its compliance with organizational policies and standards. If management approval cannot be obtained or if the exemption is not justified, the auditor may need to report the control process weakness to senior management (option C) for further action. However, the initial step should be to confirm the legitimacy of the exemption through verifying management's approval.
KAP2HURUF 👍 2 Selected: D
Option B, "Review the list of end users and evaluate for authorization," could be considered as a potential course of action, but it's not the immediate next step.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Per ISACA audit standards, when a control deficiency is identified, the auditor must first investigate whether a formal exception exists. Option D requires confirming if management has officially approved the absence of reviews, which could eliminate the finding entirely. As noted in community discussion, verifying authorization ensures the auditor understands the business rationale before proceeding (Comment 7). This aligns with the fundamental audit cycle of evidence collection and validation prior to reporting.

Why the Other Options Are Wrong

Option A relies on verbal confirmation, which lacks the documentary evidence required for audit compliance. Option B focuses on individual user data rather than the control process itself, making it irrelevant to the procedural gap. Option C escalates prematurely; reporting to senior management is only appropriate after confirming the issue is unauthorized and unmitigated.

Community Comment Notes

Candidates are split between options B and D, reflecting a tension between tactical verification and strategic audit procedure. Several users correctly note that management cannot simply approve exemptions without proper governance, yet the auditor’s immediate duty is to check existing documentation (Comment 1, Comment 5). Others mistakenly jump to escalation, overlooking the standard requirement to validate exemptions first (Comment 3). The consensus highlights that understanding policy exceptions precedes all corrective actions.

Official Reference

Exam Strategy

Always follow the audit investigation sequence: identify the gap, verify documentation or exemptions, then assess impact before escalating. Never report a deficiency until you have ruled out authorized management approvals or compensating controls.

Frequently Asked Questions

Why is verifying an exemption better than reviewing user lists?

Audits prioritize process validation over individual data checks. Confirming documented approvals addresses the systemic control gap directly.

Can management legally approve skipping access reviews?

Only if properly governed and risk-assessed. The auditor must verify written authorization exists before classifying the gap as a deficiency.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide