CISA D1: Information System Auditing Process
CISA Domain 1 (18% weight) covers how an IS audit is planned, performed, and reported: ISACA's IT Audit Framework (ITAF), risk-based audit planning, control types, sampling, evidence collection, data analytics, and communicating results. Every other CISA domain is tested through the lens this domain sets up, so it pays to master it first.
The biggest mindset shift for CISSP and CISM holders: on CISA, you are the auditor, not the implementer. The auditor evaluates controls, gathers evidence, reports findings, and recommends improvements. When an answer choice has the auditor designing, fixing, or operating a control, it is almost always wrong, because doing so would impair the auditor's independence.
ITAF standards
ISACA's IT Audit Framework groups its standards into three series: General (1000 series: audit charter, independence, objectivity, due professional care, proficiency), Performance (1200 series: risk assessment in planning, engagement planning, supervision, evidence, using the work of others), and Reporting (1400 series: reporting and follow-up). Know which series a scenario falls under; the exam doesn't expect individual standard numbers.
Audit risk model
Audit risk = inherent risk × control risk × detection risk. Inherent risk exists before any controls. Control risk is the chance controls fail to prevent or detect a material error. Detection risk is the chance the auditor's own procedures miss it. The auditor can only directly influence detection risk, by changing the nature, timing, and extent of testing (for example, a larger sample when control risk is high).
Risk-based audit planning
Audit effort goes to the areas of highest risk to the organization, not evenly across every system or on a fixed rotation. Planning starts with understanding the business, its processes, and its risks; only then are audit objectives, scope, and procedures set.
Evidence reliability
Evidence is more reliable when it comes from a source independent of the auditee, when the auditor obtains it directly (observation, reperformance, recomputation) rather than being told, and when it is documentary rather than oral. A system report the auditor ran personally beats a spreadsheet the auditee prepared.
Control self-assessment (CSA)
Workshops where process owners assess their own controls, with the auditor acting as facilitator. CSA supplements the audit function and builds control ownership in the business. It does not replace traditional audit, and questions implying it does are testing exactly that point.
CAATs and data analytics
Computer-assisted audit techniques (generalized audit software, embedded audit modules, test data, data analytics) let the auditor test an entire population or audit continuously instead of sampling. The auditor must confirm the integrity of the extracted data and should work on a copy, never by querying live production in ways that could change it.
Reporting and follow-up
Findings are discussed with the auditee before the report is finalized, to confirm the facts, but the auditor decides what goes in the report. Management owns corrective action; the auditor follows up to confirm it happened. If management accepts a risk the auditor considers unacceptable, the auditor documents it and escalates to senior management or the audit committee rather than dropping the finding.
Compliance testing vs. substantive testing
Compliance tests check whether a control is operating as designed (were purchase orders approved before payment?). Substantive tests check the actual integrity of the data or transactions (are the recorded amounts correct?). Weak controls found in compliance testing call for more substantive testing, not less.
Attribute sampling vs. variable sampling
Attribute sampling estimates a rate of occurrence (how often a control failed, a yes/no per item) and pairs with compliance testing. Variable sampling estimates a monetary or quantitative value (total misstatement in a balance) and pairs with substantive testing. Stop-or-go and discovery sampling are both forms of attribute sampling.
Audit charter vs. engagement letter
The audit charter establishes the internal audit function's overall authority, scope, and accountability, and is approved by the board or audit committee. An engagement letter defines one specific engagement, and is more common for external auditors. Questions about where audit authority comes from point to the charter.
Recommend vs. implement
The auditor recommends; management implements. An answer where the auditor writes the fix, configures the control, or takes over a process is an independence problem, even if it would work. The best auditor action is usually to report the issue to the appropriate level of management.
Sources: ; ; ;
CISA practice exams are in development. Get every CISA domain in one printable guide, free with an account.
Get the Complete Guide