What Should an IS Auditor Do Next After Finding SDLC Deficiencies?

Audit Process & Reporting
Answer Correct answer: D — communicate the SDLC policy deficiencies to the auditee to verify facts and allow corrective action before formal documentation.

An IS auditor has identified deficiencies within the organization's software development life cycle policies. Which of the following should be done NEXT?

  1. Escalate the situation to the lead auditor.
  2. Identify who approved the policies.
  3. Document the findings in the audit report.
  4. Communicate the observation to the auditee. Correct Answer

Community Votes

D
71%
C
29%

71% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the mandatory sequence of audit fieldwork, where validating findings with management must precede formal documentation, often trapping candidates into choosing immediate reporting.

After identifying SDLC policy deficiencies, CISA best practices dictate communicating the observation directly to the auditee first to verify facts and allow for timely corrective action. Community consensus strongly supports this sequential audit approach over immediate reporting or escalation.

Option C is frequently selected because candidates assume confirmed deficiencies must be immediately recorded, overlooking that audit standards require prior validation and discussion with the auditee.

Community Discussion (6 comments)

RS66 👍 1 Selected: D
D. Communicate the observation to the auditee.
Swallows 👍 1 Selected: D
While options such as escalating the situation to the lead auditor (option A) may be necessary in certain circumstances, it's generally advisable to start by communicating the observation to the auditee. This allows the organization to respond to the findings and take appropriate actions promptly.
Swallows 👍 3 Selected: D
Before issuing an audit report, the auditor works with the auditee to verify the facts of the findings.
Swallows 👍 1 Selected: C
Prior to issuing an audit report, auditor review the facts of our findings with the auditee.
MJORGER 👍 2
D. Communicate the observation to the auditee. Documenting the findings in the audit report is essential, but it should come after communicating the observations to the auditee. The auditee should have an opportunity to respond or take corrective action before the findings are formally documented.
marc4354345 👍 1 Selected: C
C makes most sense to me.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

According to ISACA and IIA auditing standards, fieldwork requires direct communication with the auditee upon identifying a deficiency. This step validates facts, gathers necessary context, and provides management an opportunity to implement quick fixes before formal reporting. As noted in community feedback, discussing observations first ensures the audit remains collaborative and factually accurate [1][2].

Why the Other Options Are Wrong

Documenting findings immediately (C) bypasses the mandatory validation phase and risks reporting unverified or misunderstood issues. Escalating to the lead auditor (A) prematurely disrupts normal audit workflows and should only occur if the auditee refuses to engage or the risk is critical. Identifying policy approvers (B) is irrelevant to the immediate next step and delays addressing the operational deficiency.

Community Comment Notes

Candidates consistently emphasize that audit reports should never be issued without prior auditee review [5]. Multiple voters highlight that early communication allows organizations to take corrective action promptly, which aligns with best practices for continuous improvement [4]. While some initially lean toward documentation, experienced professionals confirm that validation always precedes formal recording [2].

Official Reference

Exam Strategy

Always map your answer to the chronological audit lifecycle rather than focusing solely on the severity of the finding. Prioritize verification and stakeholder communication steps before moving to documentation or escalation phases.

Frequently Asked Questions

Why document findings after communicating with the auditee?

Audit standards require validating facts with management first to ensure accuracy and allow immediate remediation before formal reporting.

Is escalating to the lead auditor appropriate immediately?

Escalation is reserved for severe compliance breaches or uncooperative management, not initial deficiency identification.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide