How to confirm a software application is no longer in scope for external reporting?
The internal audit team determines a software application is no longer in scope for external reporting requirements. Which of the following will confirm that the application is no longer applicable?
Community Votes
67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your ability to identify the formal governance mechanism that confirms a system's removal from a compliance scope, with the common trap being confusing operational data reviews with formal sign-off procedures.
When an internal audit determines a software application is no longer in scope for external reporting, acknowledgement and attestation provide the formal documented sign-off needed to confirm its removal from scope. Community consensus strongly favors attestation as the definitive control to verify applicability changes.
Many candidates choose 'Data inventory and retention' (Option A) because it seems logical to verify data relevance first; however, an inventory is an investigative tool, not the formal confirmation mechanism that attestation provides.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Acknowledgement and attestation (Option D) provides the formal, documented sign-off from authorized parties confirming that the application is no longer applicable for external reporting requirements. In GRC frameworks, attestation serves as the auditable evidence that stakeholders have reviewed and agreed upon the change in scope. This documented confirmation is what auditors and regulators require to validate that a system has been properly removed from compliance obligations.Why the Other Options Are Wrong
Option A (Data inventory and retention) is an operational process used to identify what data exists and how long it should be kept, but it does not constitute formal confirmation of scope removal. Option B (Right to be forgotten) is a privacy regulation concept related to data subject requests, not scope determination. Option C (Due care and due diligence) represents the general legal and ethical obligation to act responsibly, but it is too broad and abstract to serve as specific confirmation documentation.Community Comment Notes
The vote split (67 for D, 33 for A) reveals significant confusion between investigative processes and formal confirmation mechanisms. Comment [1] advocates for Option A, arguing that data inventory helps confirm whether an application still processes relevant data, which is a reasonable operational step but not the final confirmation. Comments [2], [3], and [4] correctly identify that attestation provides the documented and verifiable statement needed to formally affirm the change in status, which aligns with audit and compliance requirements.Official Reference
Exam Strategy
When a question asks what will 'confirm' or 'verify' a governance decision, look for formal documentation and sign-off mechanisms like attestation rather than operational processes. Distinguish between tools used to investigate a situation and the formal evidence used to document the conclusion.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →