What is the first step in a project risk evaluation?

IT Project Management
Answer Correct answer: C — Review the organization's project management framework.

Halfway through an enterprise-wide project to implement business solutions, an IS auditor is called in to do a project risk evaluation. The results from this audit are to be communicated directly to the project steering committee. What should the auditor do FIRST?

  1. Assess the project organization and actual cost incurred.
  2. Interview the project manager about the project scope and current status.
  3. Review the organization's project management framework. Correct Answer
  4. Perform a risk assessment of the project based on best practices.

Community Votes

C
70%
B
30%

70% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the sequence of an IS audit, specifically the need to understand the control environment (framework) before gathering evidence (interviews), avoiding the trap of jumping into data collection too early.

When conducting a project risk evaluation, the auditor must first establish the criteria for assessment. The community consensus confirms that reviewing the organization's project management framework is the necessary initial step to understand the methodologies used.

Choosing to interview the project manager (Option B) is a common mistake because gathering information without first establishing the evaluation criteria leads to an unstructured audit.

Community Discussion (4 comments)

Rachy 👍 7 Selected: C
Firstly review the project management framework to understand the methodologies being used to carry out the project
blehbleh 👍 1 Selected: B
Interview first
PurpleParrot 👍 1 Selected: B
The first step should be to interview the project manager to understand the project context
Swallows 👍 1 Selected: B
While reviewing the project management framework is important, it is not the first step. Priority should be given to gathering information focusing on the specific status, progress and risks of the project.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An IS auditor must first understand the environment and the standards against which the project will be measured. Reviewing the project management framework provides the necessary context and criteria to evaluate the project's risk effectively. Without this baseline, any subsequent assessment lacks a defined scope and standard.

Why the Other Options Are Wrong

Interviewing the project manager (Option B) is a data-gathering activity that should occur after the criteria are established. Assessing costs (Option A) is a specific audit step that comes later in the process. Performing a risk assessment based on best practices (Option D) is premature; organizational frameworks take precedence over generic best practices.

Community Comment Notes

The majority of the community (70 votes) supports reviewing the framework first. Comment [1] highlights that this step is crucial to understand the methodologies used, while dissenting comments [2, 3, 4] incorrectly prioritize immediate information gathering over establishing the audit basis.

Official Reference

Exam Strategy

For 'FIRST' questions in auditing, always look for the step that establishes the baseline or criteria. Remember the audit process: Understand, Assess, Test, Report.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide