Which Document Includes an Audit's Quality Assurance Process?
Which of the following documents is MOST likely to include an audit's quality assurance (QA) process?
Community Votes
50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests knowledge of audit governance documentation, with the common trap being confusing operational evaluation tools (post-audit reviews) with the foundational governing document that mandates QA.
The audit charter formally establishes the internal audit function's framework and mandates compliance with the IIA's Quality Assurance and Improvement Program, aligning with expert consensus despite community debate over post-audit reviews.
Post-audit review (B) is frequently chosen because it directly evaluates audit performance, but it is an operational activity rather than the foundational document that establishes the overarching QA framework.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The audit charter serves as the formal mandate for the internal audit department and must explicitly reference compliance with the IIA Standards. Per International Professional Practices Framework (IPPF) Standard 1300, the charter should state that the audit activity maintains a Quality Assurance and Improvement Program covering all aspects of conformance. This makes it the primary document establishing the QA process rather than just executing it.Why the Other Options Are Wrong
A post-audit review is a tactical step within the QA program, not the governing document itself. Audit scope focuses on specific engagement boundaries, while the audit report details final findings. These options confuse operational execution with the foundational governance document that mandates the entire QA framework.Community Comment Notes
Candidates are frequently split between the charter and post-audit reviews, but authoritative references like comment [1] and [4] correctly cite IIA requirements linking the charter to the QA program. Comment [3] accurately explains that the charter sets the foundational framework for quality assurance across all engagements. While some argue for post-audit reviews, they overlook the critical distinction between a procedural activity and the official governing document.Official Reference
Exam Strategy
Always distinguish between governing documents (charters, policies) and operational procedures (reviews, reports) when questions ask about frameworks or mandates. Look for keywords like 'formally establish,' 'mandate,' or 'framework' to point toward the charter.
Frequently Asked Questions
Why isn't post-audit review the correct answer?
Post-audit review is an operational activity within the QA program, not the foundational document that mandates the entire framework. The charter legally authorizes and establishes the QA process.
Does the audit charter detail specific QA testing steps?
No, it only states the mandate to maintain a QA program and comply with IIA standards. Detailed testing steps belong in QA manuals or standard operating procedures.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →