Certified Information Systems Auditor (CISA) — Question 266
Upon completion of audit work, an IS auditor should:
Answer options
- A. provide a report to the auditee stating the initial findings.
- B. provide a report to senior management prior to discussion with the auditee.
- C. distribute a summary of general findings to the members of the auditing team.
- D. review the working papers with the auditee.
Correct answer: A
Explanation
The correct answer is A because the IS auditor's primary responsibility is to inform the auditee of the initial findings to ensure transparency and address any concerns. Options B and C are incorrect as they focus on communication with management or team members rather than the auditee. Option D is also not correct since reviewing working papers with the auditee comes after reporting initial findings.