Which practice best supports effectiveness of a compliance program?
Which of the following BEST supports the effectiveness of a compliance program?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests whether you can distinguish measurable program outcomes from compliance enablers, and the trap is to select a GRC tool because it automates tracking.
The CISA-aligned best support for compliance program effectiveness is assessing and tracking compliance audit findings, not simply deploying a GRC tool. This page explains why option A is correct, compares each alternative, and reviews the community debate.
Selecting B, implementing a GRC tool, because it appears to 'track compliance'; however, a tool only records information unless the audit findings are actively assessed and remediated.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Assessing and tracking all compliance audit findings creates the closed-loop evidence needed to prove a compliance program actually works. When an organization reviews audit findings, it identifies gaps between practice and regulations, assigns remediation, and verifies closure — exactly the type of measurable activity that supports effectiveness. Under ISACA’s audit perspective, objective audit results carry more weight than process artifacts, making option A the strongest indicator of program effectiveness.
Why the Other Options Are Wrong
Option B, a GRC tool, is the main distractor: it helps store and display compliance data, but implementing a system does not by itself make the program effective — people and processes must act on what the tool reports. Option C only confirms which regulations apply; that is an initial scoping step, not evidence that compliance is achieved. Option D, an awareness plan, supports employee knowledge and culture, but education without follow-up measurement and remediation cannot demonstrate effectiveness.
Community Comment Notes
Commenters such as KAP2HURUF supported option A because assessing audit findings is a “proactive approach” to identifying, documenting, and addressing gaps in compliance posture. Hermfrancis called the question controversial, pointing out that “For IS auditor, A For Management, B” while others agreed that tracking findings is a key process for remediation. The community consensus in this thread favors A, even while recognizing why management stakeholders might prefer tool-based tracking.
Exam Strategy
When CISA asks “BEST supports” a program, ask what produces measurable evidence of continuous improvement rather than what merely enables compliance work. Track audit findings and remediation outcomes, and avoid selecting a GRC tool solely because it automates compliance tracking.
Frequently Asked Questions
Why is implementing a GRC tool not the best answer for compliance program effectiveness?
A GRC tool only stores and tracks data; effectiveness comes from assessing audit findings and acting on remediation, which the tool alone does not guarantee.
Does monitoring which regulations apply support compliance? Why is it wrong?
Monitoring applicable regulations is only scoping; it does not prove that the organization actually follows them. Audit finding assessment closes that gap.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →