Greatest Concern in Outsourced Payroll Audit
An IS auditor is reviewing a client’s outsourced payroll system to assess whether the financial audit team can rely on the application. Which of the following findings would be the auditor's GREATEST concern?
Community Votes
57% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the hierarchy of controls where contractual legality underpins all operational assurances; missing legal review invalidates the audit trail.
This CISA question evaluates the auditor's ability to identify risks in outsourced services, with community consensus leaning toward legal non-compliance as the primary barrier to reliance.
Candidates often select option B (access reviews) because it is a tangible security control, but overlook that without a valid contract, access rights are irrelevant.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The greatest concern is D because the third-party contract has not been reviewed by the legal department. In ISACA methodology, a legally binding and compliant contract is the foundational element of vendor management. Without legal validation, the organization cannot enforce Service Level Agreements (SLAs), data protection clauses, or audit rights, making it impossible for the financial audit team to rely on the system.Why the Other Options Are Wrong
Option A is incorrect because budgeting issues do not directly impact the reliability or integrity of the payroll application. Option B is a significant risk regarding data security, but access controls are secondary to the contractual framework that governs the relationship. Option C is less critical than D because while policy non-compliance is an internal issue, the lack of legal review exposes the organization to unenforceable terms and regulatory violations, which is a more fundamental failure.Community Comment Notes
Comment [1] highlights that ISACA questions prioritize legal oversight for third-party contracts. Comment [4] argues for C, but the consensus among experienced auditors is that legal validity (D) precedes internal policy compliance (C). Comments [2] and [3] favor B due to security concerns, but this misses the strategic governance perspective required for outsourcing audits.Official Reference
Exam Strategy
When evaluating outsourcing scenarios, always check for the existence of a valid, legally reviewed contract first. Operational controls like access reviews are important, but they depend entirely on the contractual right to implement and audit them.
Frequently Asked Questions
Why isn't user access review the biggest risk?
Access reviews protect data confidentiality, but without a legally valid contract, you have no enforceable right to demand those reviews or audit the vendor.
What is the difference between C and D?
C is an internal policy violation, while D is a fundamental legal exposure. Legal review ensures the contract is enforceable and compliant with laws, which is prerequisite for any reliance.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →