Next Step When Periodic Access Reviews Are Missing | CISA
An IS auditor finds that periodic reviews of read-only users for a reporting system are not being performed. Which of the following should be the IS auditor's NEXT course of action?
Community Votes
50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the audit principle of validating authorized exceptions before escalating deficiencies, with the common trap being premature reporting or jumping to granular user data checks.
When an IS auditor discovers unperformed periodic access reviews, verifying documented management approval for an exemption is the required next step. CISA methodology prioritizes investigation over immediate escalation to prevent false positives.
Option B is frequently selected because auditors instinctively want to validate individual accounts, but this ignores the procedural context and potential authorized management exemptions.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Per ISACA audit standards, when a control deficiency is identified, the auditor must first investigate whether a formal exception exists. Option D requires confirming if management has officially approved the absence of reviews, which could eliminate the finding entirely. As noted in community discussion, verifying authorization ensures the auditor understands the business rationale before proceeding (Comment 7). This aligns with the fundamental audit cycle of evidence collection and validation prior to reporting.Why the Other Options Are Wrong
Option A relies on verbal confirmation, which lacks the documentary evidence required for audit compliance. Option B focuses on individual user data rather than the control process itself, making it irrelevant to the procedural gap. Option C escalates prematurely; reporting to senior management is only appropriate after confirming the issue is unauthorized and unmitigated.Community Comment Notes
Candidates are split between options B and D, reflecting a tension between tactical verification and strategic audit procedure. Several users correctly note that management cannot simply approve exemptions without proper governance, yet the auditor’s immediate duty is to check existing documentation (Comment 1, Comment 5). Others mistakenly jump to escalation, overlooking the standard requirement to validate exemptions first (Comment 3). The consensus highlights that understanding policy exceptions precedes all corrective actions.Official Reference
Exam Strategy
Always follow the audit investigation sequence: identify the gap, verify documentation or exemptions, then assess impact before escalating. Never report a deficiency until you have ruled out authorized management approvals or compensating controls.
Frequently Asked Questions
Why is verifying an exemption better than reviewing user lists?
Audits prioritize process validation over individual data checks. Confirming documented approvals addresses the systemic control gap directly.
Can management legally approve skipping access reviews?
Only if properly governed and risk-assessed. The auditor must verify written authorization exists before classifying the gap as a deficiency.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →