What is the first step in a project risk evaluation?
Halfway through an enterprise-wide project to implement business solutions, an IS auditor is called in to do a project risk evaluation. The results from this audit are to be communicated directly to the project steering committee. What should the auditor do FIRST?
Community Votes
70% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the sequence of an IS audit, specifically the need to understand the control environment (framework) before gathering evidence (interviews), avoiding the trap of jumping into data collection too early.
When conducting a project risk evaluation, the auditor must first establish the criteria for assessment. The community consensus confirms that reviewing the organization's project management framework is the necessary initial step to understand the methodologies used.
Choosing to interview the project manager (Option B) is a common mistake because gathering information without first establishing the evaluation criteria leads to an unstructured audit.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An IS auditor must first understand the environment and the standards against which the project will be measured. Reviewing the project management framework provides the necessary context and criteria to evaluate the project's risk effectively. Without this baseline, any subsequent assessment lacks a defined scope and standard.Why the Other Options Are Wrong
Interviewing the project manager (Option B) is a data-gathering activity that should occur after the criteria are established. Assessing costs (Option A) is a specific audit step that comes later in the process. Performing a risk assessment based on best practices (Option D) is premature; organizational frameworks take precedence over generic best practices.Community Comment Notes
The majority of the community (70 votes) supports reviewing the framework first. Comment [1] highlights that this step is crucial to understand the methodologies used, while dissenting comments [2, 3, 4] incorrectly prioritize immediate information gathering over establishing the audit basis.Official Reference
Exam Strategy
For 'FIRST' questions in auditing, always look for the step that establishes the baseline or criteria. Remember the audit process: Understand, Assess, Test, Report.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →