Greatest Fraud Risk: Mandatory Leave vs Access Reviews

Organizational Governance and IT Management
Answer Correct answer: D — The organization does not require employees to take mandatory leave.

Which of the following would be of GREATEST concern to an IS auditor assessing the organizational risk associated with fraud?

  1. Unauthorized changes to the production environment have been detected.
  2. Periodic user access reviews to financial systems are inconsistent.
  3. A major financial application is developed and maintained by the application team.
  4. The organization does not require employees to take mandatory leave. Correct Answer

Community Votes

B
40%
A
40%
D
20%

40% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests knowledge of preventive controls for fraud; the trap is choosing operational security issues over specific anti-fraud mechanisms.

IS auditors prioritize mandatory leave as a key fraud prevention control, making its absence the greatest risk compared to inconsistent access reviews.

Community Discussion (5 comments)

PurpleParrot 👍 1 Selected: A
Option A
RS66 👍 1 Selected: A
A. Unauthorized changes to the production environment have been detected.
Swallows 👍 2 Selected: B
Inconsistent periodic user access reviews to financial systems can pose significant risks related to fraud. Proper access controls are crucial in preventing unauthorized access to financial data and systems, which could be exploited by individuals intending to commit fraud. Inconsistent reviews may result in outdated user access permissions, potentially allowing unauthorized users to manipulate financial data or perform fraudulent activities without detection. This could lead to financial losses, regulatory compliance issues, and damage to the organization's reputation. Therefore, ensuring consistent and thorough user access reviews is critical for mitigating fraud risks within an organization.
MJORGER 👍 1 Selected: D
D is wright.
MJORGER 👍 3
ChatGpt and page 99 from Cisa 27th Study Guide: D. The organization does not require employees to take mandatory leave. This practice, known as "mandatory leave" or "forced vacation," is a preventive control measure commonly used to mitigate the risk of fraud. Requiring employees to take time off allows for their work to be scrutinized by others in their absence, making it more difficult for fraudulent activities to go undetected. It serves as a deterrent to fraudulent behavior and provides an opportunity for irregularities or anomalies in employee activities to be identified.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Mandatory leave (forced vacation) is a critical detective control for fraud because it prevents a single individual from maintaining continuous control over a process without oversight. When an employee is away, their duties are performed by others who may uncover irregularities or concealed fraudulent activities. The absence of this policy represents a significant gap in internal controls specifically designed to mitigate fraud risk.

Why the Other Options Are Wrong

Inconsistent user access reviews (Option B) are important for general security and compliance but are less directly linked to immediate fraud detection than mandatory leave. Unauthorized changes to production (Option A) indicate a security breach or lack of change management integrity but do not inherently imply fraud. Option C describes a development model which may have segregation of duties issues but is not the greatest concern for fraud specifically compared to the lack of a mandatory leave policy.

Community Comment Notes

Comments highlight that while access reviews are vital, the CISA study guide emphasizes mandatory leave as a primary fraud deterrent. Users note that forced vacation allows for independent review of work, making it harder to hide long-term fraud schemes.

Official Reference

Array

Exam Strategy

When asked about 'fraud' specifically, look for controls that enable detection through separation of time or role, such as mandatory leave or job rotation, rather than general security controls like patching or access logs.

Frequently Asked Questions

Why is mandatory leave better than access reviews for fraud?

Mandatory leave forces a handover where others perform duties, often revealing hidden fraud. Access reviews check permissions but don't necessarily detect ongoing illicit transactions.

Is unauthorized production change a fraud risk?

It indicates poor change management and potential security breaches, but it is not a direct indicator of financial fraud unless linked to data theft or manipulation.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide