First Step Auditing IT Portfolio Management Process

IT Audit & Assurance
Answer Correct answer: C — Verify whether the IT project portfolio is kept up to date before proceeding with any audit activities.

Which of the following should be done FIRST when auditing an IT portfolio management process at a large organization?

  1. Conduct walk-through meetings with IT project managers.
  2. Calculate the IT portfolio return on investment (ROI).
  3. Verify whether the IT project portfolio is kept up to date. Correct Answer
  4. Confirm industry best practices for IT portfolio management are followed.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tested is the logical sequence of audit procedures, with the common trap being jumping straight into stakeholder walkthroughs or financial calculations before validating data integrity.

This question tests the foundational steps of an IT portfolio audit, establishing that verifying portfolio currency must precede detailed analysis or stakeholder interviews. The correct approach ensures audit evidence reflects actual organizational priorities rather than outdated records.

Option A is frequently selected because walk-throughs feel like standard audit initiation, but interviewing project managers without confirming the portfolio's accuracy yields unreliable baseline data.

Community Discussion (3 comments)

ruckie 👍 1
Should be A. During walk through thats when C happens.
Binagr8 👍 1
When auditing an IT portfolio management process at a large organization, the FIRST step should be: C. Verify whether the IT project portfolio is kept up to date. Ensuring that the IT project portfolio is current is essential before performing other audit activities. If the portfolio is not up to date, any subsequent analysis, such as calculating ROI or assessing best practices, would be based on outdated information, leading to potentially inaccurate or misleading conclusions. Starting with this verification ensures that the audit is based on accurate and relevant data.
Swallows 👍 3 Selected: C
After verifying the currency of the IT project portfolio (option C), the auditor can then proceed to conduct walk-through meetings with IT project managers (option A) to gather more detailed information about specific projects, their management practices, and challenges. This sequential approach ensures that the audit is thorough and systematically addresses key aspects of the IT portfolio management process. Therefore, option C, verifying whether the IT project portfolio is kept up to date, is the appropriate first step when auditing an IT portfolio management process at a large organization.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Validating whether the IT project portfolio is current is the essential first step because all subsequent audit procedures depend on accurate, up-to-date information. Auditing standards require assessors to establish the reliability of underlying data before performing deeper reviews or calculating metrics like ROI. Without this verification, any findings regarding best practices or financial performance would be built on potentially obsolete or incomplete records.

Why the Other Options Are Wrong

Conducting walk-through meetings is valuable but logically follows data validation, as discussions lack focus if the documented projects do not reflect reality. Calculating ROI requires validated project lists and financial data, making it premature before confirming portfolio currency. Confirming adherence to industry best practices involves benchmarking against established frameworks, which cannot be accurately assessed until the scope and contents of the portfolio are verified.

Community Comment Notes

Several learners emphasize that checking portfolio updates naturally precedes detailed project discussions, aligning with systematic audit planning. As Swallows noted, verifying currency allows auditors to then conduct targeted walk-throughs efficiently. Others point out that calculating ROI or assessing best practices becomes meaningless if the underlying project list is stale, reinforcing the need for initial data validation.

Exam Strategy

Always prioritize data integrity checks before moving to analytical or interview-based audit procedures. When evaluating process audits, ask yourself what foundational information must be confirmed to make subsequent steps meaningful.

Frequently Asked Questions

Why can't we start with walk-through meetings?

Walk-throughs rely on existing documentation; if the portfolio is outdated, interviews will address irrelevant or missing projects, wasting audit time.

Is calculating ROI ever a first step?

No, ROI calculations require verified project data and funding records, making them dependent on prior portfolio validation.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide