Next Step for Improperly Tested Controls in Control Self-Assessment

Audit Planning & Execution
Answer Correct answer: D — Perform additional testing to complement CSA activities and independently verify control effectiveness before issuing reports or providing guidance.

As part of control self-assessment (CSA) activities in the finance department, an IS auditor identified that some of the controls were not tested and documented properly. Which of the following should the auditor do NEXT?

  1. Provide guidance regarding control objectives to staff involved in the CSA.
  2. Expand the scope of the next internal audit planned for the finance department.
  3. Issue an audit report to the finance manager regarding the inadequate testing of controls.
  4. Perform additional testing to complement CSA activities in the finance department. Correct Answer

Community Votes

D
57%
A
43%

57% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests CISA audit methodology priorities, trapping candidates who jump to training or reporting instead of verifying findings first.

When an IS auditor discovers inadequate testing during a control self-assessment, determining the proper next step is critical for audit validity. This page explains why independent verification testing takes precedence over immediate reporting or training.

Option A is frequently chosen because auditors want to fix the root cause, but providing guidance prematurely skips the essential step of validating control effectiveness through independent testing.

Community Discussion (4 comments)

pLulu 👍 1
Performing additional testing (Option D) can indeed help ensure that the controls are adequately assessed and documented. However, it's important to address the root cause of why the controls were not properly tested and documented in the first place. Providing guidance regarding control objectives to the staff involved in the CSA (Option A) helps ensure that future CSA activities are conducted correctly. This proactive approach can prevent similar issues from occurring again and improve the overall effectiveness of the CSA process.
blehbleh 👍 3 Selected: A
This is A not D. It is a CSA the auditor should provide guidance so they can improve their CSA.
Binagr8 👍 4
It is A. A. Provide guidance regarding control objectives to staff involved in the CSA. This would be the most suitable next action, as the auditor should focus on helping the finance department staff understand the control objectives and improve their own testing and documentation of controls as part of the CSA process.
Swallows 👍 4 Selected: D
Given that the IS auditor has identified that some controls in the finance department were not properly tested and documented during control self-assessment (CSA) activities, the immediate next step should be to perform additional testing. This is necessary to ensure that these controls are adequately assessed and documented, which is essential for providing reliable assurance through the CSA process.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

When an IS auditor identifies deficiencies in how controls were tested and documented during a control self-assessment, the immediate priority is to gather sufficient, competent evidence. Performing additional independent testing directly validates the actual operating effectiveness of those controls before any conclusions are drawn. This step ensures the audit opinion rests on objective verification rather than relying solely on potentially flawed self-reported data.

Why the Other Options Are Wrong

Providing guidance regarding control objectives (Option A) addresses future improvements but bypasses the critical need to verify current control status. Expanding the scope of the next internal audit (Option B) delays necessary validation and shifts focus away from the immediate finding. Issuing an audit report to the finance manager (Option C) prematurely escalates unverified observations, which violates fundamental audit evidence requirements.

Community Comment Notes

Several candidates initially favored Option A, believing that helping staff understand control objectives would resolve the documentation gap immediately. As user Swallows noted, "Performing additional testing can indeed help ensure that the controls are adequately assessed," emphasizing the need for direct verification. The discussion highlights a common tension between remediation and validation, where independent testing ultimately serves as the necessary bridge before corrective actions or formal reporting.

Exam Strategy

Always prioritize gathering sufficient, competent evidence before escalating issues or recommending process changes. In CISA scenarios, verify the auditor's immediate action against the audit lifecycle phases rather than jumping to remediation.

Frequently Asked Questions

Why isn't providing guidance the immediate next step?

Guidance addresses future prevention, but auditors must first validate current control effectiveness through independent testing to establish factual baseline data.

Does performing additional testing duplicate the CSA work?

No. CSA relies on management's self-evaluation, while independent testing provides objective, third-party evidence required for audit assurance.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide