How should an auditor test an automated daily data flow for completeness?
Which of the following is the MOST appropriate testing approach when auditing a daily data flow between two systems via an automated interface to confirm that it is complete and accurate?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam distinguishes substantive testing of actual data transfers from configuration, output examples, or security control reviews; data reconciliation is the only option that verifies daily completeness and accuracy.
Data reconciliation is the core audit test for confirming completeness and accuracy of an automated daily data flow. This page explains why a 25-day reconciliation sample is the correct CISA exam answer.
Choosing B because inspecting interface configurations and an example output seems direct, but an example output cannot prove that all daily records were transferred completely and accurately over time.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option D is the correct answer because data reconciliation compares the records in the source system with the records in the receiving system for a sample of 25 days. This directly tests whether the daily automated data flow is complete and accurate over a meaningful period. For a daily flow, a 25-day sample gives the auditor representative evidence that the interface is working correctly on multiple days, not just on one occasion.Why the Other Options Are Wrong
Option A, conducting code review and inspecting design documentation, is a review of how both systems were built rather than a substantive test of whether the daily data actually gets transferred accurately. Option B, inspecting interface configurations and an example output, confirms the interface is configured and that a single sample output looks plausible, but it does not verify that every day's complete data set is transmitted. Option C, confirming encryption standards, addresses confidentiality and security, but the question asks about completeness and accuracy, not protection of the data in transit.Community Comment Notes
Swallows explained that data reconciliation compares data from one system with data from another system to ensure consistency and accuracy. marc4354345 reinforced the idea that to confirm data flow is complete, auditors must examine full data, not just an "Example output would not be enough." MJORGER argued for option B, but configuration review plus one example output still fails to demonstrate that the daily flow is complete over a representative sample of many business days.Official Reference
Exam Strategy
For CISA auditor-response questions, ask yourself which option provides substantive evidence about the actual processing risk named in the question. When the risk is data completeness and accuracy, choose a test that compares real data across systems over multiple days, not configuration review or security controls.
Frequently Asked Questions
Why is inspecting interface configurations and one example output not sufficient for this audit?
Because it only proves the interface is set up and one output looks correct; it does not verify that complete, accurate data is exchanged every day over time.
Why is a 25-day sample better than code review when testing a daily data flow?
Data reconciliation over 25 sample days tests actual daily transfer outcomes, while code review only checks design and build and cannot detect operational data loss.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →