712-50 Question 61
Single answerUnderstand the IT audit process and be familiar with IT audit standardsA newly appointed CISO is preparing for the organization's first enterprise-wide IT audit after a major ERP migration. Internal audit has proposed using a controls checklist developed for the legacy environment, while the external auditors have asked management to demonstrate that the audit approach is risk-based and aligned to recognized IT audit standards. The CISO wants to ensure the audit will provide meaningful assurance to the audit committee without wasting time on low-value testing. Which action should the CISO take FIRST to best align the audit with accepted IT audit practice?
- A
Require the auditors to reuse the legacy checklist so results can be compared directly year over year
- B
Define the audit scope and objectives based on a current risk assessment of the ERP environment, then map controls and testing to a recognized audit framework
- C
Ask the ERP project manager to identify only the technical controls that were newly implemented so the audit can focus exclusively on recent changes
- D
Defer the audit until the ERP environment has been stable for at least one year to avoid reporting temporary control issues
Show answer and explanation
Correct answer: B
Explanation
The best first step is to establish a risk-based audit scope and objectives for the current environment, then align testing to recognized IT audit standards or frameworks. This reflects core audit principles found in ISACA's IT assurance guidance and the IIA's risk-based internal auditing approach: auditors should perform planning based on risk assessment, materiality, and control objectives relevant to the environment under review. After a major ERP migration, relying on a legacy checklist is weak practice because the technology stack, process flows, roles, integrations, and risk profile may have changed materially. A proper IT audit process typically includes planning, risk assessment, scope definition, control identification, fieldwork/testing, evaluation, reporting, and follow-up. Recognized references include ISACA's ITAF, COBIT as a control/governance reference, and IIA Standards requiring risk-based engagement planning. In this scenario, the CISO should first ensure the audit plan is grounded in current risks and mapped to accepted standards so the audit committee receives relevant and credible assurance.
- A. Incorrect.
This is incorrect because reusing a legacy checklist without reassessing risks can lead to misaligned audit procedures, omitted risks, and unnecessary testing of controls that are no longer relevant. IT audits should be risk-based and reflect the current environment, especially after a major system migration. Year-over-year comparability is useful, but it should not override the need to update scope, control objectives, and test procedures.
- B. Correct.
This is correct because accepted IT audit practice begins with understanding the business context, identifying risks, and defining audit objectives and scope accordingly. A current risk assessment helps ensure the audit addresses the most significant risks introduced by the ERP migration, such as segregation of duties, interface integrity, change management, privileged access, and configuration management. Mapping the audit to a recognized framework or standard supports consistency, defensibility, and stakeholder confidence in the audit approach.
- C. Incorrect.
This is incorrect because focusing only on newly implemented technical controls is too narrow and ignores broader audit considerations. ERP migrations affect business processes, governance, user access, data migration, interfaces, and compensating controls, not just new technical safeguards. This option reflects a common misconception that post-implementation audits should only examine technology changes rather than the full control environment and related business risks.
- D. Incorrect.
This is incorrect because delaying the audit would reduce timely assurance during a period of elevated risk. Major migrations often introduce control gaps, and early post-implementation review is a recognized good practice to identify issues before they become entrenched. While some stabilization may be necessary, postponing the audit for a full year is not aligned with a risk-based approach when management and the audit committee need prompt assurance.