Greatest Concern in Outsourced Payroll Audit

IT Audit and Assurance
Answer Correct answer: D — The third-party contract has not been reviewed by the legal department.

An IS auditor is reviewing a client’s outsourced payroll system to assess whether the financial audit team can rely on the application. Which of the following findings would be the auditor's GREATEST concern?

  1. Payroll processing costs have not been included in the IT budget.
  2. User access rights have not been periodically reviewed by the client.
  3. The third-party contract does not comply with the vendor management policy.
  4. The third-party contract has not been reviewed by the legal department. Correct Answer

Community Votes

D
57%
B
43%

57% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the hierarchy of controls where contractual legality underpins all operational assurances; missing legal review invalidates the audit trail.

This CISA question evaluates the auditor's ability to identify risks in outsourced services, with community consensus leaning toward legal non-compliance as the primary barrier to reliance.

Candidates often select option B (access reviews) because it is a tangible security control, but overlook that without a valid contract, access rights are irrelevant.

Community Discussion (7 comments)

blehbleh 👍 1 Selected: B
it is B
PurpleParrot 👍 2 Selected: D
option D
46080f2 👍 2 Selected: D
I vote for D., but seem to be pretty much alone in this view. The usual AI chatbot's here have different answers, but none say. D. Anyway, I'm sticking with D. The way I've understood ISACA thinking so far from many other ISACA questions is that for third-party contracts, having a contract reviewed by a Legal Department or Lawyer is paramount. At least in the questions from the official ISACA learning material, I was always right with this understanding. So I stick with D.
Sibsankar 👍 1
Sorry , It must be C
Swallows 👍 1 Selected: B
User access rights are crucial for maintaining the confidentiality, integrity, and availability of payroll data. Without periodic reviews, there's a higher risk of unauthorized access, which could lead to data breaches, fraud, or errors in financial records. This finding indicates a potential weakness in security controls, raising significant concerns about data protection and the accuracy of financial audits relying on the payroll system.
MJORGER 👍 1 Selected: B
B. User access rights have not been periodically reviewed by the client Periodic review of user access rights is crucial for maintaining security and ensuring that only authorized individuals have access to sensitive data. If these reviews are not being conducted, there could be users with inappropriate access, which poses a significant risk to data integrity and confidentiality.
Sibsankar 👍 1
Fue to its direct impact on the ability to rely on the outsourced payroll system for the financial audit, a non-compliant third-party contract is the greatest concern for the IS auditor. So, the answer will be C

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The greatest concern is D because the third-party contract has not been reviewed by the legal department. In ISACA methodology, a legally binding and compliant contract is the foundational element of vendor management. Without legal validation, the organization cannot enforce Service Level Agreements (SLAs), data protection clauses, or audit rights, making it impossible for the financial audit team to rely on the system.

Why the Other Options Are Wrong

Option A is incorrect because budgeting issues do not directly impact the reliability or integrity of the payroll application. Option B is a significant risk regarding data security, but access controls are secondary to the contractual framework that governs the relationship. Option C is less critical than D because while policy non-compliance is an internal issue, the lack of legal review exposes the organization to unenforceable terms and regulatory violations, which is a more fundamental failure.

Community Comment Notes

Comment [1] highlights that ISACA questions prioritize legal oversight for third-party contracts. Comment [4] argues for C, but the consensus among experienced auditors is that legal validity (D) precedes internal policy compliance (C). Comments [2] and [3] favor B due to security concerns, but this misses the strategic governance perspective required for outsourcing audits.

Official Reference

Exam Strategy

When evaluating outsourcing scenarios, always check for the existence of a valid, legally reviewed contract first. Operational controls like access reviews are important, but they depend entirely on the contractual right to implement and audit them.

Frequently Asked Questions

Why isn't user access review the biggest risk?

Access reviews protect data confidentiality, but without a legally valid contract, you have no enforceable right to demand those reviews or audit the vendor.

What is the difference between C and D?

C is an internal policy violation, while D is a fundamental legal exposure. Legal review ensures the contract is enforceable and compliant with laws, which is prerequisite for any reliance.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide