What Should an IS Auditor Do Next After Finding SDLC Deficiencies?
An IS auditor has identified deficiencies within the organization's software development life cycle policies. Which of the following should be done NEXT?
Community Votes
71% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the mandatory sequence of audit fieldwork, where validating findings with management must precede formal documentation, often trapping candidates into choosing immediate reporting.
After identifying SDLC policy deficiencies, CISA best practices dictate communicating the observation directly to the auditee first to verify facts and allow for timely corrective action. Community consensus strongly supports this sequential audit approach over immediate reporting or escalation.
Option C is frequently selected because candidates assume confirmed deficiencies must be immediately recorded, overlooking that audit standards require prior validation and discussion with the auditee.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
According to ISACA and IIA auditing standards, fieldwork requires direct communication with the auditee upon identifying a deficiency. This step validates facts, gathers necessary context, and provides management an opportunity to implement quick fixes before formal reporting. As noted in community feedback, discussing observations first ensures the audit remains collaborative and factually accurate [1][2].Why the Other Options Are Wrong
Documenting findings immediately (C) bypasses the mandatory validation phase and risks reporting unverified or misunderstood issues. Escalating to the lead auditor (A) prematurely disrupts normal audit workflows and should only occur if the auditee refuses to engage or the risk is critical. Identifying policy approvers (B) is irrelevant to the immediate next step and delays addressing the operational deficiency.Community Comment Notes
Candidates consistently emphasize that audit reports should never be issued without prior auditee review [5]. Multiple voters highlight that early communication allows organizations to take corrective action promptly, which aligns with best practices for continuous improvement [4]. While some initially lean toward documentation, experienced professionals confirm that validation always precedes formal recording [2].Official Reference
Exam Strategy
Always map your answer to the chronological audit lifecycle rather than focusing solely on the severity of the finding. Prioritize verification and stakeholder communication steps before moving to documentation or escalation phases.
Frequently Asked Questions
Why document findings after communicating with the auditee?
Audit standards require validating facts with management first to ensure accuracy and allow immediate remediation before formal reporting.
Is escalating to the lead auditor appropriate immediately?
Escalation is reserved for severe compliance breaches or uncooperative management, not initial deficiency identification.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →