When to Schedule Follow-Up Audits for Corrective Actions?

Audit Follow-Up / Control Testing
Answer Correct answer: C — Wait until sufficient time has elapsed since implementation to gather reliable evidence of control operation.

Which of the following would BEST guide an IS auditor when determining an appropriate time to schedule the follow-up of agreed corrective actions for reported audit issues?

  1. Business management has completed the implementation of agreed actions on schedule.
  2. Progress updates indicate that the implementation of agreed actions is on track.
  3. Sufficient time has elapsed since implementation to provide evidence of control operation. Correct Answer
  4. Regulators have announced a timeline for an inspection visit.

Community Votes

C
75%
B
25%

75% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of control validation timing versus project completion milestones, trapping candidates who prioritize administrative progress over actual control effectiveness.

This question addresses the optimal timing for auditing implemented corrective actions. The page establishes that waiting for sufficient operational evidence is superior to merely tracking completion status.

Option B is frequently chosen because progress updates sound proactive, but they only confirm execution plans rather than proving sustained control performance.

Community Discussion (4 comments)

46080f2 👍 1 Selected: C
The best guidance for an IS auditor is C. Sufficient time has elapsed since implementation to provide evidence of control operation. This ensures the auditor can review tangible evidence of how the controls perform over time, which is essential for validating their effectiveness. Completion (Option A) and progress updates (Option B) are preliminary steps, but they don’t guarantee operational success. Similarly, regulatory timelines (Option D) are secondary to the auditor’s need for evidence-based assurance. Therefore, Option C provides the strongest foundation for scheduling a follow-up audit.
choboanon 👍 1 Selected: C
A etter way to word it would be: A) We've completed the controls, are we ready for review? B)We're on track to completethe controls and sent a progress update, are we ready for review? C) We've completed the controls, and time has passed for us to have ample evidence whether or not they are operating effectively D) A Deadline was set for the review. Are they ready?
choboanon 👍 1 Selected: C
Answer is C. Be critical of anything wallows comments..
Swallows 👍 1 Selected: B
Progress updates indicating that the implementation of agreed actions is on track (option B) would best guide an IS auditor when determining an appropriate time to schedule the follow-up of agreed corrective actions for reported audit issues. This option suggests that the corrective actions are being implemented as planned and that there is evidence of progress toward addressing the identified audit issues. By ensuring that the implementation is on track, the auditor can schedule follow-up at a suitable time to verify completion and effectiveness. While other options may also provide relevant information, such as sufficient time elapsed since implementation to provide evidence of control operation (option C), progress updates indicating implementation progress offer more specific guidance on the timing of follow-up activities. Option C focuses on the passage of time rather than active progress toward resolution.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Selecting option C aligns with ISACA’s fundamental principle that controls must operate over a meaningful period before their effectiveness can be reliably evaluated. An auditor cannot validate whether a newly implemented fix actually mitigates risk without observing its performance across multiple cycles or business periods. Waiting for sufficient elapsed time ensures the audit evidence reflects real-world operating conditions rather than temporary adjustments or initial configuration states.

Why the Other Options Are Wrong

Option A focuses solely on administrative completion, which does not guarantee the control functions correctly once deployed. Option B tracks project momentum but fails to address whether the remediation actually sustains its intended security posture over time. Option D introduces an external regulatory deadline that may force premature testing before the organization has had adequate opportunity to stabilize the new control environment.

Community Comment Notes

Multiple learners emphasize that implementation completion does not equal operational readiness, noting that tangible evidence requires time to accumulate. One participant rephrased the scenario to highlight that passing time allows auditors to verify long-term effectiveness rather than just initial setup. Another user warned against prioritizing administrative milestones over actual control validation, reinforcing the need to observe sustained performance.

Exam Strategy

Always distinguish between project completion metrics and control effectiveness validation when scheduling audit activities. Prioritize observation periods that allow risks to be tested under normal operating conditions rather than chasing administrative deadlines.

Frequently Asked Questions

Why is option B insufficient for scheduling follow-ups?

Progress updates only confirm execution plans, not sustained control performance or actual risk mitigation over time.

Does management completion guarantee audit readiness?

No, administrative completion lacks the necessary observation period to prove the control operates effectively in production.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide