Which Document Includes an Audit's Quality Assurance Process?

Internal Audit Governance
Answer Correct answer: A — The audit charter formally establishes and mandates the department-wide Quality Assurance and Improvement Program framework.

Which of the following documents is MOST likely to include an audit's quality assurance (QA) process?

  1. Audit charter Correct Answer
  2. Post-audit review
  3. Audit scope
  4. Audit report

Community Votes

A
50%
B
50%

50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of audit governance documentation, with the common trap being confusing operational evaluation tools (post-audit reviews) with the foundational governing document that mandates QA.

The audit charter formally establishes the internal audit function's framework and mandates compliance with the IIA's Quality Assurance and Improvement Program, aligning with expert consensus despite community debate over post-audit reviews.

Post-audit review (B) is frequently chosen because it directly evaluates audit performance, but it is an operational activity rather than the foundational document that establishes the overarching QA framework.

Community Discussion (5 comments)

ruckie 👍 1
"Quality Assurance and Improvement Program – The charter should include: o A statement that the internal audit activity will maintain a quality assurance and improvement program that covers all aspects of the internal audit activity including its evaluation of conformance to IIA Standards. o A requirement for the CAE to report periodically the results of its quality assurance and improvement program to senior management and the governing body..." this doesn't itemize the process so B is most accurate
PurpleParrot 👍 2 Selected: A
As per the IIA, an audit charter should have Quality Assurance and Improvement Program. Option A is correct
RS66 👍 2 Selected: B
B. Post-audit review
jan1234 👍 2 Selected: B
The correct answer is B. Post-audit review. A post-audit review is a process that evaluates the quality of an audit engagement after its completion. It assesses the effectiveness of the audit process, identifies areas for improvement, and provides recommendations for enhancing the quality of future audits. This review is a key component of an audit's quality assurance (QA) process.
Swallows 👍 2 Selected: A
The audit charter typically outlines the overall framework, objectives, scope, and responsibilities of the audit, including its quality assurance (QA) processes. It sets the foundation for the audit and includes details on how quality will be ensured throughout the audit process. While the other documents might touch upon QA processes, the audit charter is specifically designed to establish these processes from the outset.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The audit charter serves as the formal mandate for the internal audit department and must explicitly reference compliance with the IIA Standards. Per International Professional Practices Framework (IPPF) Standard 1300, the charter should state that the audit activity maintains a Quality Assurance and Improvement Program covering all aspects of conformance. This makes it the primary document establishing the QA process rather than just executing it.

Why the Other Options Are Wrong

A post-audit review is a tactical step within the QA program, not the governing document itself. Audit scope focuses on specific engagement boundaries, while the audit report details final findings. These options confuse operational execution with the foundational governance document that mandates the entire QA framework.

Community Comment Notes

Candidates are frequently split between the charter and post-audit reviews, but authoritative references like comment [1] and [4] correctly cite IIA requirements linking the charter to the QA program. Comment [3] accurately explains that the charter sets the foundational framework for quality assurance across all engagements. While some argue for post-audit reviews, they overlook the critical distinction between a procedural activity and the official governing document.

Official Reference

Exam Strategy

Always distinguish between governing documents (charters, policies) and operational procedures (reviews, reports) when questions ask about frameworks or mandates. Look for keywords like 'formally establish,' 'mandate,' or 'framework' to point toward the charter.

Frequently Asked Questions

Why isn't post-audit review the correct answer?

Post-audit review is an operational activity within the QA program, not the foundational document that mandates the entire framework. The charter legally authorizes and establishes the QA process.

Does the audit charter detail specific QA testing steps?

No, it only states the mandate to maintain a QA program and comply with IIA standards. Detailed testing steps belong in QA manuals or standard operating procedures.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide