712-50 Question 71
Single answerDevelop an IT audit documentation process and share reports with relevant stakeholders as the basis for decision-makingA newly appointed CISO is standardizing the organization's IT audit documentation process after several board members complained that audit reports are inconsistent, too technical, and do not clearly support risk-based decisions. Internal audit, IT operations, compliance, and business unit leaders all receive the same report, which often causes confusion about priorities and ownership. The CISO wants a process that improves traceability from evidence to findings, supports remediation tracking, and ensures that each stakeholder receives information useful for decision-making. Which of the following is the MOST effective approach?
- A
Create a standardized audit documentation framework that includes scope, criteria, evidence, risk-rated findings, root cause, business impact, management response, remediation owner, and target date; then issue audience-specific reporting views such as detailed reports for control owners and executive summaries for senior leadership
- B
Distribute the full technical audit workpapers to all stakeholders so that everyone can review the raw evidence directly and interpret the results without filtering
- C
Limit the final audit report to a list of control failures and affected systems, leaving risk interpretation and remediation prioritization to each business unit to avoid central bias
- D
Publish only a dashboard of open findings and due dates because concise metrics are sufficient for audit governance and reduce the burden of maintaining formal documentation
Show answer and explanation
Correct answer: A
Explanation
The best answer is the standardized documentation framework with role-based reporting. In a mature IT audit documentation process, the organization should maintain complete and defensible records of audit scope, objectives, criteria, methods, evidence, findings, and conclusions. Findings should be tied to business impact and risk severity, and include management action plans, assigned owners, and target completion dates. This supports both remediation governance and accountability. At the same time, reporting should be tailored: operational teams need detailed corrective-action information, while senior management and the board need aggregated, risk-focused summaries that help them make funding, prioritization, and oversight decisions. This aligns with common audit and governance best practices reflected in frameworks such as ISACA audit guidance, IIA reporting principles, and control governance models that emphasize evidence traceability, consistency, stakeholder relevance, and actionable reporting.
- A. Correct.
Correct. This approach establishes a repeatable audit documentation process with the core elements expected in mature audit and governance practices: defined scope and criteria, traceable evidence, risk-rated findings, root cause analysis, business impact, management response, ownership, and due dates. It also recognizes that different stakeholders need different levels of detail. Control owners need enough information to act, while executives and the board need concise, risk-oriented summaries to support prioritization and resource decisions. This directly supports accountability, remediation tracking, and decision-making.
- B. Incorrect.
Incorrect. Sharing full technical workpapers with all stakeholders is inefficient and can create confidentiality, interpretation, and information overload issues. Workpapers are important for audit trail and quality assurance, but they are not the primary communication vehicle for executives or business leaders. Stakeholders should receive information tailored to their role, not raw evidence without context.
- C. Incorrect.
Incorrect. A list of control failures without risk interpretation, root cause, business impact, and assigned ownership weakens the usefulness of the report. Audit reporting should enable management action and informed prioritization. Leaving each business unit to interpret severity independently often leads to inconsistent treatment of risk and poor enterprise-level governance.
- D. Incorrect.
Incorrect. Dashboards are useful for status monitoring, but they do not replace formal audit documentation. A dashboard alone usually lacks sufficient context on audit objectives, testing performed, evidence, risk rationale, and management responses. Without this supporting documentation, traceability, defensibility, and meaningful decision support are reduced.