What Should an IS Auditor Prioritize in a Financial App RFP?

System Acquisition & Development
Answer Correct answer: A — Ensure the financial application meets the organization’s documented functional and security requirements before finalizing vendor selection.

An IS auditor is providing input to an RFP to acquire a financial application system. Which of the following is MOST important for the auditor to recommend?

  1. The application should meet the organization's requirements. Correct Answer
  2. Vendor employee background checks should be conducted regularly.
  3. Audit trails should be included in the design.
  4. Potential suppliers should have experience in the relevant area.

Community Votes

A
83%
C
17%

83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of the auditor's primary procurement objective, where candidates often mistakenly prioritize specific technical controls over holistic business requirement alignment.

When drafting an RFP for a financial application, IS auditors must prioritize ensuring the solution aligns with the organization's specific functional and security requirements. Community consensus strongly agrees that meeting business needs takes precedence over isolated technical controls like audit trails.

Option C is frequently chosen because auditors naturally focus on monitoring and compliance, but it represents a single control rather than the comprehensive foundation required for any enterprise acquisition.

Community Discussion (3 comments)

Vima234 👍 1 Selected: C
Given that the question specifically asks what an auditor should recommend, the most relevant choice for the auditor's perspective is: C. Audit trails should be included in the design. From an IS auditor's point of view, ensuring that audit trails are included in the system design is critical. Audit trails provide a means to track user activities, detect unauthorized access or modifications, and support the accountability and integrity of financial data. This recommendation directly aligns with the auditor’s role in ensuring that controls are in place to support security, compliance, and data integrity within the system
RS66 👍 2 Selected: A
A. The application should meet the organization's requirements.
MJORGER 👍 3 Selected: A
A key objective of the RFP process is to select a vendor or solution that best meets the organization's needs and requirements. Therefore, it is essential for the IS auditor to emphasize that the financial application system should align with the organization's specific functional, technical, and security requirements.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The primary objective of an IS auditor during the procurement phase is to guarantee that the selected solution aligns with the organization’s overarching business and operational requirements. Option A correctly identifies this foundational step, as failing to define and enforce comprehensive requirements leads to costly mismatches, security gaps, and project failures. By embedding requirement validation into the RFP, the auditor ensures the financial system delivers intended value while satisfying regulatory mandates.

Why the Other Options Are Wrong

Option C focuses exclusively on audit trails, which are merely one component of a broader control framework rather than the primary procurement driver. Option B addresses vendor personnel screening, a valuable risk mitigation tactic that falls under due diligence rather than core system specification. Option D highlights supplier experience, which is useful for qualification scoring but does not substitute for explicit organizational requirement alignment.

Community Comment Notes

Community feedback strongly validates Option A, emphasizing that RFP evaluation must start with business need fulfillment before isolating specific technical controls. Several users noted that while audit trails are critical for financial systems, they are inherently subordinate to the comprehensive requirement baseline established in the initial RFP phase. This consensus aligns with ISACA’s guidance that auditor recommendations must prioritize holistic organizational alignment over fragmented feature requests.

Official Reference

Exam Strategy

Always evaluate auditor recommendations through the lens of business value and comprehensive requirement alignment first. Isolate specific technical controls as secondary to overarching organizational needs during procurement phases.

Frequently Asked Questions

Why isn't audit trail inclusion the top priority in an RFP?

Audit trails are a vital control but represent only one component of system design. Business requirement alignment encompasses functionality, security, compliance, and operational needs, making it the foundational priority.

Does background checking vendors matter more than requirements?

Vendor vetting is important for risk mitigation, but without clear organizational requirements driving the RFP, even thoroughly screened vendors may deliver an unsuitable solution.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide