MTC Group
← All Study Guides

D1: Information System Auditing Process

CISA (ISACA) study guide

CISA D1: Information System Auditing Process

CISA Domain 1 (18% weight) covers how an IS audit is planned, performed, and reported: ISACA's IT Audit Framework (ITAF), risk-based audit planning, control types, sampling, evidence collection, data analytics, and communicating results. Every other CISA domain is tested through the lens this domain sets up, so it pays to master it first.

The biggest mindset shift for CISSP and CISM holders: on CISA, you are the auditor, not the implementer. The auditor evaluates controls, gathers evidence, reports findings, and recommends improvements. When an answer choice has the auditor designing, fixing, or operating a control, it is almost always wrong, because doing so would impair the auditor's independence.

Key Concepts
  • ITAF standards

    ISACA's IT Audit Framework groups its standards into three series: General (1000 series: audit charter, independence, objectivity, due professional care, proficiency), Performance (1200 series: risk assessment in planning, engagement planning, supervision, evidence, using the work of others), and Reporting (1400 series: reporting and follow-up). Know which series a scenario falls under; the exam doesn't expect individual standard numbers.

  • Audit risk model

    Audit risk = inherent risk × control risk × detection risk. Inherent risk exists before any controls. Control risk is the chance controls fail to prevent or detect a material error. Detection risk is the chance the auditor's own procedures miss it. The auditor can only directly influence detection risk, by changing the nature, timing, and extent of testing (for example, a larger sample when control risk is high).

  • Risk-based audit planning

    Audit effort goes to the areas of highest risk to the organization, not evenly across every system or on a fixed rotation. Planning starts with understanding the business, its processes, and its risks; only then are audit objectives, scope, and procedures set.

  • Evidence reliability

    Evidence is more reliable when it comes from a source independent of the auditee, when the auditor obtains it directly (observation, reperformance, recomputation) rather than being told, and when it is documentary rather than oral. A system report the auditor ran personally beats a spreadsheet the auditee prepared.

  • Control self-assessment (CSA)

    Workshops where process owners assess their own controls, with the auditor acting as facilitator. CSA supplements the audit function and builds control ownership in the business. It does not replace traditional audit, and questions implying it does are testing exactly that point.

  • CAATs and data analytics

    Computer-assisted audit techniques (generalized audit software, embedded audit modules, test data, data analytics) let the auditor test an entire population or audit continuously instead of sampling. The auditor must confirm the integrity of the extracted data and should work on a copy, never by querying live production in ways that could change it.

  • Reporting and follow-up

    Findings are discussed with the auditee before the report is finalized, to confirm the facts, but the auditor decides what goes in the report. Management owns corrective action; the auditor follows up to confirm it happened. If management accepts a risk the auditor considers unacceptable, the auditor documents it and escalates to senior management or the audit committee rather than dropping the finding.

Confusable Pairs
  • Compliance testing vs. substantive testing

    Compliance tests check whether a control is operating as designed (were purchase orders approved before payment?). Substantive tests check the actual integrity of the data or transactions (are the recorded amounts correct?). Weak controls found in compliance testing call for more substantive testing, not less.

  • Attribute sampling vs. variable sampling

    Attribute sampling estimates a rate of occurrence (how often a control failed, a yes/no per item) and pairs with compliance testing. Variable sampling estimates a monetary or quantitative value (total misstatement in a balance) and pairs with substantive testing. Stop-or-go and discovery sampling are both forms of attribute sampling.

  • Audit charter vs. engagement letter

    The audit charter establishes the internal audit function's overall authority, scope, and accountability, and is approved by the board or audit committee. An engagement letter defines one specific engagement, and is more common for external auditors. Questions about where audit authority comes from point to the charter.

  • Recommend vs. implement

    The auditor recommends; management implements. An answer where the auditor writes the fix, configures the control, or takes over a process is an independence problem, even if it would work. The best auditor action is usually to report the issue to the appropriate level of management.

Sources

Sources: ; ; ;

CISA practice exams are in development. Get every CISA domain in one printable guide, free with an account.

Get the Complete Guide

We use essential cookies to run this site, and, only with your consent, advertising cookies from Google, LinkedIn, and Reddit to measure ad performance. See our for details.