Certified Information Systems Auditor (CISA) — Question 1104
During planning for a cloud service audit, audit management becomes aware that the assigned IS auditor is unfamiliar with the technologies in use and their associated risks to the business. To ensure audit quality, which of the following actions should audit management consider FIRST?
Answer options
- A. Conduct a follow-up audit after a suitable period has elapsed.
- B. Reassign the audit to an internal audit subject matter expert.
- C. Reschedule the audit assignment for the next financial year.
- D. Extend the duration of the audit to give the auditor more time.
Correct answer: B
Explanation
The correct action is to reassign the audit to an internal audit subject matter expert, as they possess the necessary knowledge and skills to evaluate the technologies and risks effectively. The other options, such as postponing the audit or extending its duration, do not address the fundamental issue of the auditor's lack of expertise, which could compromise the audit's effectiveness.