The audit doesn't start when the auditor arrives at the client site — it starts with a risk-based plan. Domain 1 establishes the professional framework that governs every IS audit engagement: how you plan where to look, and how you execute — the methods, evidence, testing, and communication that turn audit objectives into defensible findings.
Planning tells you where to look; execution is how you look
Domain 1 is the largest single domain at 18% of the exam, and it is the conceptual spine of the whole credential. Everything else — governance, systems, operations, security — is something the auditor evaluates using the discipline established here. This lesson runs the full engagement lifecycle in two halves: Planning (Domain 1A) — standards and ethics, audit types, risk-based planning, and controls; and Execution (Domain 1B) — project management, testing and sampling, evidence, analytics, reporting, and quality assurance. Throughout, hold the auditor's stance: evaluate, test, document, and report — independently and on the basis of evidence.
Every IS audit follows the same engagement lifecycle — plan where to look (by risk), execute the fieldwork and gather evidence, report findings and an opinion, then follow up to confirm remediation — and the cycle repeats.
Learning Objectives
By the end of this lesson you will be able to…
Apply ISACA IS audit standards, guidelines, and the Code of Professional Ethics to audit engagements. Bloom: Apply
Distinguish among the types of audits, assessments, and reviews used in IS audit practice. Bloom: Analyze
Develop a risk-based audit plan that prioritizes engagements according to organizational risk exposure. Bloom: Create
Classify controls by type and nature, and assess adequacy versus effectiveness. Bloom: Apply
Identify threats to auditor independence and objectivity and apply appropriate mitigation strategies. Bloom: Remember
Select appropriate audit tests, sampling methods, and evidence-collection techniques, including CAATs. Bloom: Evaluate
Apply audit data analytics to test full populations and detect anomalies. Bloom: Apply
An IS audit is only credible if it follows recognized professional standards. ISACA publishes a tiered body of authoritative guidance that tells an auditor what they must do, how they may do it, and the ethics that bind them. Every exam scenario assumes you are operating inside this framework, so it is the foundation for everything that follows.
ITAF and the three tiers of guidance
ISACA gathers this guidance into ITAF (the IT Assurance Framework) — the single overarching framework that houses the three tiers below and sets the professional practices for the audit function. Everything from the mandatory standards to the hands-on techniques lives inside ITAF.
IS Audit & Assurance Standards (S1–S16) — mandatory minimum requirements. They cover the audit charter (S1), organizational and professional independence (S2, S3), reasonable expectation (S4), due professional care (S5), proficiency (S6), assertions and criteria (S7, S8), planning (S9), supervision (S10), materiality (S11), using the work of other experts (S12), evidence (S13), use of CAATs (S14), reporting (S15), and follow-up (S16).
Guidelines — non-mandatory guidance that elaborates on how to apply the standards in practice.
Audit charter (S1) — the document that protects the auditor’s independence: it authorizes access to all records, systems, and personnel, and is approved by the board or audit committee, not by the management being audited.
Assertions & criteria (S7, S8) — audit objectives are framed as the management assertions being tested (existence, completeness, accuracy, valuation, rights/obligations, presentation) against defined criteria.
Materiality (S11) — what is significant enough to matter; set quantitatively or qualitatively, it drives how wide the audit scope is and which findings rise to the level of being reported.
Using the work of other experts (S12) — you may rely on specialists (penetration testers, other auditors), but the originating auditor remains responsible for the conclusion and must assess the expert’s competence, objectivity, and scope.
💡 Exam TipWhenever a scenario questions the auditor’s authority or independence, the answer is the audit charter — it must be approved above management and grant unrestricted access to records and staff.
The Code of Professional Ethics
ISACA's Code binds every candidate and certificate holder to act with objectivity and due care, serve stakeholders lawfully, maintain confidentiality, sustain professional competency, inform appropriate parties of results (disclosing all material facts), and support stakeholder education.
Threats to independence
Self-review — auditing one's own prior work.
Advocacy — promoting a client's position.
Familiarity — over-reliance on close relationships.
Intimidation — actual or perceived pressure.
Financial interest — ownership or compensation conflicts.
🔎 In practice
An auditor asked to review a control they personally helped design last year faces a self-review threat. The correct response is to disclose the conflict and reassign the work — not to "proceed with extra care."
💡 Exam TipWhen a scenario gives an auditor a personal, financial, or prior-engagement relationship with the auditee, the answer almost always involves disclosing the conflict and/or reassigning the engagement — not simply proceeding with added care.
2
Types of Audits, Assessments & Reviews
Objective 2 · audit types
Not every engagement has the same objective, and the objective dictates the procedures. The exam repeatedly asks you to recognize what kind of audit a scenario describes, because mislabeling the engagement leads to the wrong answer.
Financial audit — examines financial records for accuracy and GAAP/IFRS compliance; IS audit supports it by evaluating IT controls over financial reporting.
Operational audit — evaluates the effectiveness and efficiency of processes.
Compliance audit — assesses adherence to laws, regulations, and policies (SOX, PCI DSS, HIPAA, GDPR).
IS audit — evaluates the adequacy, effectiveness, and efficiency of IT controls.
Integrated audit — combines financial/operational objectives with IS procedures.
Forensic audit — investigates suspected fraud; involves evidence preservation and chain of custody.
Pre- and post-implementation reviews — evaluate controls before go-live and whether objectives were met after.
Self-assessment — management-led; the auditor evaluates the quality of the self-assessment process.
🔎 In practice
"Does the change process follow policy?" is a compliance question. "Does the change process work efficiently?" is an operational question. The same process can be the subject of either — the objective is what changes.
💡 Exam TipThe exam frequently tests compliance vs. operational. Compliance asks "Does the organization follow the rules?" Performance/operational asks "Does the process work effectively and efficiently?" Identify which the scenario is measuring.
3
Risk-Based Audit Planning
Objective 3 · risk-based planning
Audit resources are always finite. Risk-based planning directs them where organizational risk is highest — and judging that allocation correctly is the single most-tested skill in Domain 1.
How the plan is built
Start from the audit universe — the complete inventory of auditable entities (processes, systems, applications, units, locations).
For each entity, assess inherent risk, evaluate existing controls (control risk), and determine the residual risk that remains.
Rank entities by residual risk and allocate the audit plan accordingly.
Scoring the audit universe
In practice each entity is scored numerically: rate impact and likelihood (commonly 1–5 each) against defined criteria, then combine them — a simple product (impact × likelihood) or a weighted model that also factors control maturity, prior findings, regulatory exposure, and time since last audit.
The resulting scores rank the universe and plot onto a risk heat map; the highest-scoring entities become the annual plan’s priorities.
Auditor: the scoring criteria and weights are documented, applied consistently, refreshed for new risk, and approved by the audit committee — so the ranking is defensible, not subjective.
Inputs to the plan
Prior audit results and open findings; regulatory requirements; organizational strategy and material changes; management and board/audit-committee direction; emerging threats.
Distinguish the annual plan (strategic scope) from the engagement-level plan (a single audit). Audit objectives must link clearly to risk; scope sets the boundaries. COBIT 2019 supports the framework.
🔎 In practice
Given twelve auditable areas (five high-risk, four medium, three low) but capacity for only six, the risk-based plan covers all five high-risk areas plus the single highest-scoring medium area — the risk ranking, not convenience, drives the choice.
💡 Exam TipIn planning scenarios the auditor always prioritizes the highest-risk areas — not the most recently audited, not what management requests, and not the most technically complex. If material new risk emerges (e.g., a breach), the plan is updated to include it.
4
Types of Controls
Objective 4 · classifying controls
Auditors classify controls so they can judge two things: whether the right kind of control exists for a given risk, and whether that control is both well-designed and actually working.
By objective
Preventive (block before it happens — access controls, input validation), detective (identify after — logs, reconciliations, IDS), corrective (remedy — backup restoration, patching), plus deterrent, directive, and recovery controls.
By nature
Manual (people; prone to error/override), automated (systems; consistent but can fail system-wide), and IT-dependent manual (manual steps that rely on IT-generated output).
General IT controls (GITCs): access, change, operations, physical/environmental, backup. Application controls: input, processing, output. Entity-level controls: governance and culture.
Controls are classified by when they act on a threat: deterrent and preventive controls work before the event to lower likelihood; detective, corrective, and recovery controls work after it to limit impact. A compensating control stands in when the ideal control isn’t feasible.
Adequacy vs. effectiveness
Adequacy asks whether the control is designed to address the risk. Effectiveness asks whether it is operating as designed and actually reducing risk. When a primary control isn't feasible, a compensating control must provide equivalent risk reduction. Common frameworks: COBIT 2019, NIST SP 800-53, ISO/IEC 27001/27002, and CIS Controls.
🔎 In practice
A nightly reconciliation that catches posting errors is a detective control; the access control that blocks unauthorized entry is preventive. A high-risk process often needs both.
💡 Exam TipAdequacy and effectiveness are separate. A control can be well-designed but poorly implemented (adequate but ineffective), or operate flawlessly while being the wrong control for the risk (effective but inadequate).
📚
Explore furtherCybersecurity Controls reference — an interactive guide to control families and how they map to risk. A deeper companion to this section.
Execution begins by treating the audit as a project. Before any testing, the engagement must be scoped, staffed, supervised, and documented so the work can stand on its own.
Engagement letter / notification defines purpose, scope, timing, and resources for the auditee.
Team roles: engagement lead (overall quality and conclusions), senior auditor (complex testing, supervision), staff auditor (assigned testing and workpapers). Standard S10 requires supervision proportionate to complexity and experience.
Workpaper standards: complete, accurate, concise, and logically organized — sufficient to support the audit findings and conclusions (a practical heuristic: a competent reviewer could follow the work without needing to ask the auditor).
Track open issues and exceptions during fieldwork; watch project risks such as scope creep, resource constraints, auditee non-cooperation, and timeline overruns.
🔎 In practice
A workpaper that lists the procedures performed but never ties them to a conclusion is insufficient — a reviewer can't tell what the evidence means. Every workpaper should connect to a finding or conclusion.
💡 Exam TipISACA's standard is that workpapers be sufficient to support the findings and conclusions. A useful heuristic is whether a competent reviewer could follow the work without asking the auditor — but the standard itself is about supporting conclusions. Documenting procedures without tying them to conclusions is insufficient.
6
Audit Testing & Sampling Methodology
Objective 6 · tests, sampling & CAATs
Testing produces the evidence behind every conclusion. Choosing the right test, the right sample, and understanding the risk of being wrong is core auditor craft.
Test of controls verifies a control operates as designed; test of details (substantive) verifies the underlying transactions or balances.
Sampling
Statistical sampling uses probability and can be projected to the population (random, systematic, stratified). Non-statistical (judgmental) sampling relies on auditor judgment and cannot be projected (also block and haphazard).
Sample size depends on population size, acceptable risk of incorrect acceptance, and the tolerable vs. expected deviation rate.
Sampling risk:under-reliance (alpha / Type I — concluding a good control is bad) vs. over-reliance (beta / Type II — concluding a bad control is good).
🔎 In practice
If a sample's deviation rate exceeds the tolerable rate set at planning, the control cannot be relied upon — you report it. You do not keep enlarging the sample until the numbers pass, or lower the tolerance to match the result.
💡 Exam TipBeta risk (over-reliance / Type II) is the more dangerous sampling risk — concluding controls work when they don't. Sampling-risk questions usually hinge on which risk is more consequential to audit quality.
Try it — how much testing does the risk model demand?
Sample size isn't guesswork — it falls out of the audit risk model. Set inherent and control risk and the audit risk you're willing to accept; the model returns the detection risk you can allow, and the sample size needed to earn it. Watch weak controls force you to test more.
Interactive · adjust & explore
Your judgment
Set the risks; the model sizes the test.
Risk assessment
80%
Risk before controls — how error-prone the area is.
50%
Chance controls fail to catch an error. Weaker controls → higher.
5%
Overall risk of a wrong opinion you'll accept.
Sampling parameters
8%
Highest error rate you'd still rely on the control at.
1%
Error rate you actually expect to find.
What the model returns
Risk of material misstatement
—
Allowable detection risk
—
Assurance required
—
Required sample size
—
——Set the risks to size the test.
Sample size vs. control risk
As controls weaken (control risk rises), the detection risk you can accept shrinks — so the sample grows. Your operating point (●) slides along the curve; the curve itself shifts with inherent risk, the audit-risk target, and tolerances. Assumes a large population.
Sample size at your settings Your operating point
🔎 In practice
The numbers are a teaching approximation of attribute sampling — real engagements use ISACA/AICPA tables — but the direction is exam-true: weaker controls and lower tolerance demand more evidence. And note the trap: if expected deviations reach your tolerable rate, no sample size rescues reliance — you report the deficiency, you don't keep sampling until it passes.
7
Audit Evidence Collection
Objective 6 · evidence & CAATs
Audit conclusions must rest on evidence that is both sufficient (enough) and appropriate (relevant and reliable). Reliability depends heavily on where the evidence comes from.
Reliability hierarchy (most to least): the auditor's direct observation or re-performance → documentary evidence from third parties → documentary evidence from the organization → oral evidence (inquiry).
Collection techniques: document review, interview, observation, walk-through (tracing a transaction end to end), reconciliation, and third-party confirmation.
CAATs (Computer-Assisted Audit Techniques): audit software (extract and analyze data), test data (dummy transactions through the live system), Integrated Test Facility (ITF) (a fictitious entity embedded in production), and parallel simulation (auditor re-creates processing logic and compares).
ITF vs. parallel simulation — the risk difference: ITF (and test data) push fictitious transactions inside production, which must be removed or reversed or they corrupt real data; parallel simulation re-runs the auditor’s own logic outside production, so it carries no data-corruption risk.
Protect the custody and security of confidential evidence obtained during the audit.
🔎 In practice
Test data and ITF deliberately push fictitious transactions through production. If those entries aren't completely removed or reversed when testing ends, they corrupt real data and reporting — a significant risk the auditor owns.
💡 Exam TipTest data and ITF introduce fictitious data into production. The auditor must ensure all fictitious entries are completely removed or reversed before concluding the test — failure to remove test data is a serious risk.
8
Audit Data Analytics
Objective 7 · data analytics
Analytics shift auditing from samples to entire populations — every transaction rather than a subset — dramatically improving coverage and the odds of catching anomalies.
Common applications: completeness testing, duplicate detection, gap analysis (missing sequence numbers), outlier/anomaly detection, trend analysis, and Benford's Law (deviations from expected leading-digit frequencies can signal manipulation).
Tools: ACL (Galvanize/Diligent), IDEA, Microsoft Excel, Python/R, and Tableau/Power BI for visualization.
Analytics are only as good as the data: it must be complete, accurate, and drawn from authoritative sources. Auditors must work from read-only access — DBA or production access is inappropriate.
Distinguish continuous auditing (automated testing performed by auditors) from continuous monitoring (automated control monitoring performed by management).
🔎 In practice
Running Benford's Law across an entire expense file can flag manipulated amounts that a 30-item judgmental sample would almost certainly miss — population testing changes what's findable.
💡 Exam TipAn auditor performing analytics needs read-only access to authoritative data. Holding DBA or production access is itself a control weakness — and grants the auditor capabilities that conflict with independence.
9
Reporting & Communication
Objective 8 · findings & communication
A finding only has value if it is communicated clearly and at the right time. A consistent structure makes findings defensible and actionable.
The CRAF finding structure
Condition (what was found) · Criteria (the expected standard) · Cause (root cause) · Risk/Effect (consequence) · Recommendation (how to close the gap).
The reporting process
Present findings in a draft to management for response before final issuance; management acknowledges each finding with a remediation plan and target date.
Audit opinions: unqualified (clean), qualified (minor exceptions), adverse (material weaknesses), or disclaimer (unable to form an opinion).
Critical findings discovered during fieldwork must be escalated immediately — not held for the final report. Significant issues route to the audit committee/board, preserving the audit function's independence.
🔎 In practice
An auditor who uncovers an actively exploitable security hole mid-fieldwork communicates it to management/the audit committee right away. Waiting weeks for the final report would itself be an audit-quality failure.
💡 Exam TipWhen a critical issue surfaces during fieldwork, the correct action is to communicate it immediately to the appropriate level — not wait for the final report. Timing of communication matters.
10
Quality Assurance & Improvement of the Audit Process
The audit function must hold itself to the same scrutiny it applies elsewhere. Quality assurance keeps audit work meeting professional standards and feeds continuous improvement.
Internal QA: supervision and workpaper review, engagement quality reviews for high-risk work, and internal peer review.
External QA: an independent external quality assessment of the audit function, plus ISACA peer-review programs.
Key performance indicators: audit-plan completion rate, average findings per engagement, repeat-finding rate, time from fieldwork to report issuance, and percentage of recommendations implemented on schedule.
Use those metrics to refine methodology, resource allocation, and staff development. ISACA's ITAF (IT Assurance Framework) integrates standards, guidelines, and tools into one quality framework.
🔎 In practice
A rising repeat-finding rate tells you recommendations aren't being implemented — a signal that matters to both the audit function's quality program and to management's accountability for remediation.
Scored Knowledge Check
Test your Domain 1 judgment
Ten questions across Planning (1A) and Execution (1B). Select the best answer, then submit for your score and the rationale for every item — including why the trap answers fail. Answer from the auditor's perspective.