Ensuring Project Plan Adherence in IS Auditing

Answer Correct answer: A — conduct compliance audits at major system milestones.

The BEST way to provide assurance that a project is adhering to the project plan is to:

  1. conduct compliance audits at major system milestones. Correct Answer
  2. require design reviews at appropriate points in the life cycle.
  3. have an IS auditor participate on the quality assurance (QA) team.
  4. have an IS auditor participate on the steering committee.

Community Votes

A
66%
B
34%

66% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the distinction between continuous monitoring (design reviews) and formal assurance events (milestone audits), highlighting that milestone audits provide comprehensive verification of overall progress.

The most effective method for providing assurance that a project adheres to its plan is conducting compliance audits at major milestones, as confirmed by community consensus and expert analysis.

Candidates often choose design reviews (B), assuming that frequent checks are better, but this misses the broader scope of verifying total adherence to the plan at critical junctures.

Community Discussion (5 comments)

RS66 👍 1 Selected: B
B. require design reviews at appropriate points in the life cycle.
Swallows 👍 1 Selected: B
I came to the conclusion that the answer was B, not A. By conducting regular design reviews, we could check the consistency with the plan at each stage of the project and make corrections early if necessary.
Swallows 👍 1 Selected: A
While design reviews are an important element, rather than focusing on evaluation at the design stage, compliance audits at key system milestones are more comprehensive and effective in terms of verifying overall project progress and adherence to plan.
MJORGER 👍 3 Selected: A
A. conduct compliance audits at major system milestones. Compliance audits at major system milestones provide a structured, systematic, and independent evaluation of the project’s adherence to the project plan.
joehong 👍 1 Selected: C
Option A, which suggests conducting compliance audits at major system milestones, is indeed important. However, it is not the most effective method for ongoing assurance that a project is adhering to the project plan. Compliance audits are typically conducted at specific points in time and may not capture issues that arise between these milestones. On the other hand, having an IS auditor participate on the quality assurance (QA) team (Option C) allows for continuous oversight and real-time monitoring of the project’s adherence to the project plan. This proactive approach can identify and correct deviations more promptly and ensure that the project stays aligned with its intended trajectory throughout its lifecycle.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Conducting compliance audits at major system milestones (Option A) provides structured, independent evaluation points where the entire project's status can be measured against the baseline plan. This approach ensures that significant deviations are identified early enough to allow for corrective action before they become systemic failures.

Why the Other Options Are Wrong

Design reviews (Option B) focus specifically on technical specifications rather than overall project plan adherence. Having an auditor on the QA team (Option C) compromises independence, as they become part of the operational process rather than an objective evaluator. Participation in the steering committee (Option D) offers governance oversight but lacks the specific audit mechanisms needed to verify plan adherence directly.

Community Comment Notes

Comment [1] highlights that milestone audits offer a systematic evaluation of adherence. Comment [4] reinforces that while design reviews are important, milestone audits are more comprehensive for verifying overall progress. Comment [3] represents the common trap of choosing continuous review over formal assurance checkpoints.

Official Reference

Exam Strategy

When asked about 'assurance' or 'verification' of adherence, look for options involving formal audits or reviews at defined intervals rather than ongoing operational tasks. Independence and comprehensiveness are key criteria in ISACA questions regarding audit activities.

Frequently Asked Questions

Why not design reviews for plan adherence?

Design reviews check technical specs, not overall project plan adherence like schedule or budget.

Is an auditor on the QA team independent?

No, it compromises independence as they become part of the operational quality assurance process.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide