Unrecorded IT Device Invoices in Asset Audit Follow-Up
While conducting a follow-up on an asset management audit, the IS auditor finds paid invoices for IT devices not recorded in the organization's inventory. Which of the following is the auditor's BEST course of action?
Community Votes
83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests auditor reporting responsibilities during follow-ups, with the common trap being the temptation to investigate personally instead of escalating formal findings.
When an IS auditor discovers unrecorded IT device purchases during a follow-up review, the correct response involves immediate stakeholder notification rather than isolated inquiries. This page clarifies why escalating the discrepancy to audit and operations management is the only compliant CISA-standard action.
Option B is frequently chosen because auditors naturally want to gather facts directly from staff, but this bypasses formal reporting channels and fails to address potential fraud or control failures requiring management oversight.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Finding paid invoices for assets absent from the inventory register represents a material control exception that impacts financial reporting, security posture, and compliance. ISACA guidelines mandate that auditors document and formally report such discrepancies to the appropriate management levels rather than handling them informally. Escalating to both audit and operations leadership ensures accountability, triggers a root-cause investigation, and initiates necessary corrective actions across the asset lifecycle.Why the Other Options Are Wrong
Asking asset management staff directly (Option B) risks incomplete information, potential retaliation, or delayed resolution since it lacks formal escalation. Deferring the finding to a future audit cycle (Option C) allows financial leakage and unauthorized device usage to continue unchecked. Dismissing the invoices entirely (Option D) violates fundamental auditing standards regarding material exceptions and demonstrates a lack of professional skepticism.Community Comment Notes
Learners consistently emphasize that isolated questioning can miss systemic issues, as noted by users who stress alerting multiple stakeholders for broader investigation. Several contributors highlight that formal reporting aligns with ISACA’s emphasis on management ownership of corrective actions. As one commenter phrased it, "Always assume the worst. In this case I would alert to make it known to many for investigation." This reinforces that structured communication outweighs informal fact-finding when control gaps are identified.Exam Strategy
Always prioritize formal escalation and documentation over informal inquiries when identifying control exceptions during audits. Remember that management owns the remediation process; your role is to identify, report, and verify corrective actions, not to conduct independent investigations yourself.
Frequently Asked Questions
Why shouldn't the auditor just ask the asset team where the devices are?
Direct questioning lacks formal documentation and may trigger defensive behavior or incomplete disclosures. Proper protocol requires escalating findings to management for structured investigation.
Is deferring the finding to the next audit cycle acceptable?
No. Material discrepancies like unrecorded purchases pose ongoing financial and security risks that require immediate reporting and corrective action rather than future deferral.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →