Best Approach for Low-Risk Anomalies in CISA Audits

Risk-Based Auditing / Audit Execution
Answer Correct answer: B — Deprioritize further testing of the anomalies and refocus on issues with higher risk.

Which of the following is an IS auditor’s BEST approach when low-risk anomalies have been identified?

  1. Document the anomalies in audit work papers.
  2. Deprioritize further testing of the anomalies and refocus on issues with higher risk. Correct Answer
  3. Update the audit plan to include the information collected during the audit.
  4. Ask auditees to promptly remediate the anomalies.

Community Votes

B
67%
A
33%

67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests risk-based audit execution principles while trapping candidates who assume all findings require equal testing depth regardless of impact.

This CISA question evaluates how auditors should prioritize fieldwork when encountering low-risk anomalies, establishing that risk-based resource allocation takes precedence over exhaustive low-impact testing.

Candidates often select documenting the anomalies (A) because it feels universally correct, missing the strategic priority shift toward higher-risk areas emphasized in CISA methodology.

Community Discussion (3 comments)

RS66 👍 2 Selected: B
B. Deprioritize further testing of the anomalies and refocus on issues with higher risk. B does not mean you will not document the anomalies. B is best approach.
a84n 👍 2 Selected: A
Answer A
hermfrancis 👍 2 Selected: B
B, Since A can be adopted by all kinds of abnomolies.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

B aligns with ISACA’s risk-based auditing framework, which mandates proportional allocation of audit effort. Low-risk anomalies do not warrant extensive follow-up testing when higher-impact control failures exist, making deprioritization the most efficient use of audit resources.

Why the Other Options Are Wrong

A is technically required but fails as the best approach because it ignores risk prioritization and treats all findings equally. C misapplies audit planning timing, as workpaper data informs reporting rather than mid-engagement plan updates. D violates auditor independence by pushing management into remediation actions prematurely.

Community Comment Notes

Learners correctly note that choosing B does not eliminate documentation requirements, and several highlight that option A is too generic to serve as the optimal strategy for risk-driven fieldwork [Comment 1][Comment 2].

Official Reference

Exam Strategy

Always apply the risk-based lens first in CISA execution questions; if an option explicitly mentions reallocating effort away from low-impact items toward higher risks, it usually outperforms generic procedural steps.

Frequently Asked Questions

Why isn't documenting the anomaly (A) the best answer?

Documentation is mandatory but generic; CISA prioritizes risk-based resource allocation, making strategic deprioritization the superior fieldwork decision.

Should auditors report low-risk anomalies to management immediately?

No. Low-risk items are typically summarized in the final audit report without demanding urgent remediation, preserving auditor independence and management ownership.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide