Next Step for Improperly Tested Controls in Control Self-Assessment
As part of control self-assessment (CSA) activities in the finance department, an IS auditor identified that some of the controls were not tested and documented properly. Which of the following should the auditor do NEXT?
Community Votes
57% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests CISA audit methodology priorities, trapping candidates who jump to training or reporting instead of verifying findings first.
When an IS auditor discovers inadequate testing during a control self-assessment, determining the proper next step is critical for audit validity. This page explains why independent verification testing takes precedence over immediate reporting or training.
Option A is frequently chosen because auditors want to fix the root cause, but providing guidance prematurely skips the essential step of validating control effectiveness through independent testing.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
When an IS auditor identifies deficiencies in how controls were tested and documented during a control self-assessment, the immediate priority is to gather sufficient, competent evidence. Performing additional independent testing directly validates the actual operating effectiveness of those controls before any conclusions are drawn. This step ensures the audit opinion rests on objective verification rather than relying solely on potentially flawed self-reported data.Why the Other Options Are Wrong
Providing guidance regarding control objectives (Option A) addresses future improvements but bypasses the critical need to verify current control status. Expanding the scope of the next internal audit (Option B) delays necessary validation and shifts focus away from the immediate finding. Issuing an audit report to the finance manager (Option C) prematurely escalates unverified observations, which violates fundamental audit evidence requirements.Community Comment Notes
Several candidates initially favored Option A, believing that helping staff understand control objectives would resolve the documentation gap immediately. As user Swallows noted, "Performing additional testing can indeed help ensure that the controls are adequately assessed," emphasizing the need for direct verification. The discussion highlights a common tension between remediation and validation, where independent testing ultimately serves as the necessary bridge before corrective actions or formal reporting.Exam Strategy
Always prioritize gathering sufficient, competent evidence before escalating issues or recommending process changes. In CISA scenarios, verify the auditor's immediate action against the audit lifecycle phases rather than jumping to remediation.
Frequently Asked Questions
Why isn't providing guidance the immediate next step?
Guidance addresses future prevention, but auditors must first validate current control effectiveness through independent testing to establish factual baseline data.
Does performing additional testing duplicate the CSA work?
No. CSA relies on management's self-evaluation, while independent testing provides objective, third-party evidence required for audit assurance.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →