Unrecorded IT Device Invoices in Asset Audit Follow-Up

Asset Management & Audit Reporting
Answer Correct answer: A — Notify both audit and operations management immediately so the inventory discrepancy can be formally investigated and corrected.

While conducting a follow-up on an asset management audit, the IS auditor finds paid invoices for IT devices not recorded in the organization's inventory. Which of the following is the auditor's BEST course of action?

  1. Alert both audit and operations management about the discrepancy. Correct Answer
  2. Ask the asset management staff where the devices are.
  3. Make a note of the evidence to include it in the scope of a future audit.
  4. Ignore the invoices since they are not part of the follow-up.

Community Votes

A
83%
B
17%

83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests auditor reporting responsibilities during follow-ups, with the common trap being the temptation to investigate personally instead of escalating formal findings.

When an IS auditor discovers unrecorded IT device purchases during a follow-up review, the correct response involves immediate stakeholder notification rather than isolated inquiries. This page clarifies why escalating the discrepancy to audit and operations management is the only compliant CISA-standard action.

Option B is frequently chosen because auditors naturally want to gather facts directly from staff, but this bypasses formal reporting channels and fails to address potential fraud or control failures requiring management oversight.

Community Discussion (4 comments)

46080f2 👍 1 Selected: A
When an IS auditor identifies material discrepancies during a follow-up audit—such as paid invoices for devices not recorded in inventory—the auditor must immediately escalate the issue to relevant stakeholders. According to the CISA Review Manual and supporting materials: Auditor Responsibility: The auditor must document findings and present them to management, even if the issue falls outside the initial audit scope. The source material states: "If you identify an issue outside the scope of the audit, don’t disregard it. Document the issue and present it to the client".
blehbleh 👍 2 Selected: A
As a cyber analyst I can say you never just ask individuals what is happening is where things are. Always assume the worst. In this case I would alert to make it known to many for investigation. I would just just ask the asset management team staff only. I could be wrong but I pick A.
PurpleParrot 👍 2 Selected: A
option a This action is crucial because it addresses a potential issue of asset mismanagement or oversight that could lead to financial discrepancies, compliance issues, or security vulnerabilities. By alerting both audit and operations management, the auditor ensures that the discrepancy is investigated promptly and that corrective actions can be taken to rectify the inventory records.
Hayati 👍 1 Selected: B
It's B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Finding paid invoices for assets absent from the inventory register represents a material control exception that impacts financial reporting, security posture, and compliance. ISACA guidelines mandate that auditors document and formally report such discrepancies to the appropriate management levels rather than handling them informally. Escalating to both audit and operations leadership ensures accountability, triggers a root-cause investigation, and initiates necessary corrective actions across the asset lifecycle.

Why the Other Options Are Wrong

Asking asset management staff directly (Option B) risks incomplete information, potential retaliation, or delayed resolution since it lacks formal escalation. Deferring the finding to a future audit cycle (Option C) allows financial leakage and unauthorized device usage to continue unchecked. Dismissing the invoices entirely (Option D) violates fundamental auditing standards regarding material exceptions and demonstrates a lack of professional skepticism.

Community Comment Notes

Learners consistently emphasize that isolated questioning can miss systemic issues, as noted by users who stress alerting multiple stakeholders for broader investigation. Several contributors highlight that formal reporting aligns with ISACA’s emphasis on management ownership of corrective actions. As one commenter phrased it, "Always assume the worst. In this case I would alert to make it known to many for investigation." This reinforces that structured communication outweighs informal fact-finding when control gaps are identified.

Exam Strategy

Always prioritize formal escalation and documentation over informal inquiries when identifying control exceptions during audits. Remember that management owns the remediation process; your role is to identify, report, and verify corrective actions, not to conduct independent investigations yourself.

Frequently Asked Questions

Why shouldn't the auditor just ask the asset team where the devices are?

Direct questioning lacks formal documentation and may trigger defensive behavior or incomplete disclosures. Proper protocol requires escalating findings to management for structured investigation.

Is deferring the finding to the next audit cycle acceptable?

No. Material discrepancies like unrecorded purchases pose ongoing financial and security risks that require immediate reporting and corrective action rather than future deferral.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide