Greatest Fraud Risk: Mandatory Leave vs Access Reviews
Which of the following would be of GREATEST concern to an IS auditor assessing the organizational risk associated with fraud?
Community Votes
40% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests knowledge of preventive controls for fraud; the trap is choosing operational security issues over specific anti-fraud mechanisms.
IS auditors prioritize mandatory leave as a key fraud prevention control, making its absence the greatest risk compared to inconsistent access reviews.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Mandatory leave (forced vacation) is a critical detective control for fraud because it prevents a single individual from maintaining continuous control over a process without oversight. When an employee is away, their duties are performed by others who may uncover irregularities or concealed fraudulent activities. The absence of this policy represents a significant gap in internal controls specifically designed to mitigate fraud risk.Why the Other Options Are Wrong
Inconsistent user access reviews (Option B) are important for general security and compliance but are less directly linked to immediate fraud detection than mandatory leave. Unauthorized changes to production (Option A) indicate a security breach or lack of change management integrity but do not inherently imply fraud. Option C describes a development model which may have segregation of duties issues but is not the greatest concern for fraud specifically compared to the lack of a mandatory leave policy.Community Comment Notes
Comments highlight that while access reviews are vital, the CISA study guide emphasizes mandatory leave as a primary fraud deterrent. Users note that forced vacation allows for independent review of work, making it harder to hide long-term fraud schemes.Official Reference
Exam Strategy
When asked about 'fraud' specifically, look for controls that enable detection through separation of time or role, such as mandatory leave or job rotation, rather than general security controls like patching or access logs.
Frequently Asked Questions
Why is mandatory leave better than access reviews for fraud?
Mandatory leave forces a handover where others perform duties, often revealing hidden fraud. Access reviews check permissions but don't necessarily detect ongoing illicit transactions.
Is unauthorized production change a fraud risk?
It indicates poor change management and potential security breaches, but it is not a direct indicator of financial fraud unless linked to data theft or manipulation.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →