Day 1 — Afternoon · Domain 1

Information Systems Auditing Process

The audit doesn't start when the auditor arrives at the client site — it starts with a risk-based plan. Domain 1 establishes the professional framework that governs every IS audit engagement: how you plan where to look, and how you execute — the methods, evidence, testing, and communication that turn audit objectives into defensible findings.

Session: Afternoon, Day 1 Duration: ~3 hrs Exam Weight: 18% (~27 Qs) Knowledge Check: 10 Questions

Overview

Planning tells you where to look; execution is how you look

Domain 1 is the largest single domain at 18% of the exam, and it is the conceptual spine of the whole credential. Everything else — governance, systems, operations, security — is something the auditor evaluates using the discipline established here. This lesson runs the full engagement lifecycle in two halves: Planning (Domain 1A) — standards and ethics, audit types, risk-based planning, and controls; and Execution (Domain 1B) — project management, testing and sampling, evidence, analytics, reporting, and quality assurance. Throughout, hold the auditor's stance: evaluate, test, document, and report — independently and on the basis of evidence.

1 · Planningrisk-based scope2 · Fieldworktest & gather evidence3 · Reportingfindings & opinion4 · Follow-upverify remediationContinuous, risk-based engagement cycle
Every IS audit follows the same engagement lifecycle — plan where to look (by risk), execute the fieldwork and gather evidence, report findings and an opinion, then follow up to confirm remediation — and the cycle repeats.

Learning Objectives

By the end of this lesson you will be able to…

Key Terms

Vocabulary flashcards

👈 Read the term, recall the definition, then click or press Enter to check yourself. Active recall beats re-reading.

Lesson Content

Study the material

1

IS Audit Standards, Guidelines & the Code of Ethics

Objectives 1 & 5 · standards, ethics & independence

An IS audit is only credible if it follows recognized professional standards. ISACA publishes a tiered body of authoritative guidance that tells an auditor what they must do, how they may do it, and the ethics that bind them. Every exam scenario assumes you are operating inside this framework, so it is the foundation for everything that follows.

ITAF and the three tiers of guidance

ISACA gathers this guidance into ITAF (the IT Assurance Framework) — the single overarching framework that houses the three tiers below and sets the professional practices for the audit function. Everything from the mandatory standards to the hands-on techniques lives inside ITAF.

  • IS Audit & Assurance Standards (S1–S16) — mandatory minimum requirements. They cover the audit charter (S1), organizational and professional independence (S2, S3), reasonable expectation (S4), due professional care (S5), proficiency (S6), assertions and criteria (S7, S8), planning (S9), supervision (S10), materiality (S11), using the work of other experts (S12), evidence (S13), use of CAATs (S14), reporting (S15), and follow-up (S16).
  • Guidelines — non-mandatory guidance that elaborates on how to apply the standards in practice.
  • Tools & Techniques — practical, hands-on implementation guidance.

Standards the exam singles out

  • Audit charter (S1) — the document that protects the auditor’s independence: it authorizes access to all records, systems, and personnel, and is approved by the board or audit committee, not by the management being audited.
  • Assertions & criteria (S7, S8) — audit objectives are framed as the management assertions being tested (existence, completeness, accuracy, valuation, rights/obligations, presentation) against defined criteria.
  • Materiality (S11) — what is significant enough to matter; set quantitatively or qualitatively, it drives how wide the audit scope is and which findings rise to the level of being reported.
  • Using the work of other experts (S12) — you may rely on specialists (penetration testers, other auditors), but the originating auditor remains responsible for the conclusion and must assess the expert’s competence, objectivity, and scope.
💡 Exam TipWhenever a scenario questions the auditor’s authority or independence, the answer is the audit charter — it must be approved above management and grant unrestricted access to records and staff.

The Code of Professional Ethics

ISACA's Code binds every candidate and certificate holder to act with objectivity and due care, serve stakeholders lawfully, maintain confidentiality, sustain professional competency, inform appropriate parties of results (disclosing all material facts), and support stakeholder education.

Threats to independence

  • Self-review — auditing one's own prior work.
  • Advocacy — promoting a client's position.
  • Familiarity — over-reliance on close relationships.
  • Intimidation — actual or perceived pressure.
  • Financial interest — ownership or compensation conflicts.
🔎 In practice

An auditor asked to review a control they personally helped design last year faces a self-review threat. The correct response is to disclose the conflict and reassign the work — not to "proceed with extra care."

💡 Exam TipWhen a scenario gives an auditor a personal, financial, or prior-engagement relationship with the auditee, the answer almost always involves disclosing the conflict and/or reassigning the engagement — not simply proceeding with added care.
2

Types of Audits, Assessments & Reviews

Objective 2 · audit types

Not every engagement has the same objective, and the objective dictates the procedures. The exam repeatedly asks you to recognize what kind of audit a scenario describes, because mislabeling the engagement leads to the wrong answer.

  • Financial audit — examines financial records for accuracy and GAAP/IFRS compliance; IS audit supports it by evaluating IT controls over financial reporting.
  • Operational audit — evaluates the effectiveness and efficiency of processes.
  • Compliance audit — assesses adherence to laws, regulations, and policies (SOX, PCI DSS, HIPAA, GDPR).
  • IS audit — evaluates the adequacy, effectiveness, and efficiency of IT controls.
  • Integrated audit — combines financial/operational objectives with IS procedures.
  • Forensic audit — investigates suspected fraud; involves evidence preservation and chain of custody.
  • Third-party / service-provider audit — evaluates vendor controls; includes SOC 1/2/3 report review.
  • Pre- and post-implementation reviews — evaluate controls before go-live and whether objectives were met after.
  • Self-assessment — management-led; the auditor evaluates the quality of the self-assessment process.
🔎 In practice

"Does the change process follow policy?" is a compliance question. "Does the change process work efficiently?" is an operational question. The same process can be the subject of either — the objective is what changes.

💡 Exam TipThe exam frequently tests compliance vs. operational. Compliance asks "Does the organization follow the rules?" Performance/operational asks "Does the process work effectively and efficiently?" Identify which the scenario is measuring.
3

Risk-Based Audit Planning

Objective 3 · risk-based planning

Audit resources are always finite. Risk-based planning directs them where organizational risk is highest — and judging that allocation correctly is the single most-tested skill in Domain 1.

How the plan is built

  • Start from the audit universe — the complete inventory of auditable entities (processes, systems, applications, units, locations).
  • For each entity, assess inherent risk, evaluate existing controls (control risk), and determine the residual risk that remains.
  • Rank entities by residual risk and allocate the audit plan accordingly.

Scoring the audit universe

  • In practice each entity is scored numerically: rate impact and likelihood (commonly 1–5 each) against defined criteria, then combine them — a simple product (impact × likelihood) or a weighted model that also factors control maturity, prior findings, regulatory exposure, and time since last audit.
  • The resulting scores rank the universe and plot onto a risk heat map; the highest-scoring entities become the annual plan’s priorities.
  • Auditor: the scoring criteria and weights are documented, applied consistently, refreshed for new risk, and approved by the audit committee — so the ranking is defensible, not subjective.

Inputs to the plan

  • Prior audit results and open findings; regulatory requirements; organizational strategy and material changes; management and board/audit-committee direction; emerging threats.
  • Distinguish the annual plan (strategic scope) from the engagement-level plan (a single audit). Audit objectives must link clearly to risk; scope sets the boundaries. COBIT 2019 supports the framework.
🔎 In practice

Given twelve auditable areas (five high-risk, four medium, three low) but capacity for only six, the risk-based plan covers all five high-risk areas plus the single highest-scoring medium area — the risk ranking, not convenience, drives the choice.

💡 Exam TipIn planning scenarios the auditor always prioritizes the highest-risk areas — not the most recently audited, not what management requests, and not the most technically complex. If material new risk emerges (e.g., a breach), the plan is updated to include it.
4

Types of Controls

Objective 4 · classifying controls

Auditors classify controls so they can judge two things: whether the right kind of control exists for a given risk, and whether that control is both well-designed and actually working.

By objective

  • Preventive (block before it happens — access controls, input validation), detective (identify after — logs, reconciliations, IDS), corrective (remedy — backup restoration, patching), plus deterrent, directive, and recovery controls.

By nature

  • Manual (people; prone to error/override), automated (systems; consistent but can fail system-wide), and IT-dependent manual (manual steps that rely on IT-generated output).
  • General IT controls (GITCs): access, change, operations, physical/environmental, backup. Application controls: input, processing, output. Entity-level controls: governance and culture.
BEFORE — reduce likelihoodAFTER — reduce impacteventDeterrentwarning bannersPreventiveMFA, locksDetectivelogs, IDSCorrectivepatch, restoreRecoverybackups, DRPCompensating — stand-in for an infeasible primary control
Controls are classified by when they act on a threat: deterrent and preventive controls work before the event to lower likelihood; detective, corrective, and recovery controls work after it to limit impact. A compensating control stands in when the ideal control isn’t feasible.

Adequacy vs. effectiveness

Adequacy asks whether the control is designed to address the risk. Effectiveness asks whether it is operating as designed and actually reducing risk. When a primary control isn't feasible, a compensating control must provide equivalent risk reduction. Common frameworks: COBIT 2019, NIST SP 800-53, ISO/IEC 27001/27002, and CIS Controls.

🔎 In practice

A nightly reconciliation that catches posting errors is a detective control; the access control that blocks unauthorized entry is preventive. A high-risk process often needs both.

💡 Exam TipAdequacy and effectiveness are separate. A control can be well-designed but poorly implemented (adequate but ineffective), or operate flawlessly while being the wrong control for the risk (effective but inadequate).
5

Audit Project Management

Execution begins by treating the audit as a project. Before any testing, the engagement must be scoped, staffed, supervised, and documented so the work can stand on its own.

  • Engagement letter / notification defines purpose, scope, timing, and resources for the auditee.
  • Team roles: engagement lead (overall quality and conclusions), senior auditor (complex testing, supervision), staff auditor (assigned testing and workpapers). Standard S10 requires supervision proportionate to complexity and experience.
  • Phases: planning → fieldwork/execution → reporting → follow-up.
  • Workpaper standards: complete, accurate, concise, and logically organized — sufficient to support the audit findings and conclusions (a practical heuristic: a competent reviewer could follow the work without needing to ask the auditor).
  • Track open issues and exceptions during fieldwork; watch project risks such as scope creep, resource constraints, auditee non-cooperation, and timeline overruns.
🔎 In practice

A workpaper that lists the procedures performed but never ties them to a conclusion is insufficient — a reviewer can't tell what the evidence means. Every workpaper should connect to a finding or conclusion.

💡 Exam TipISACA's standard is that workpapers be sufficient to support the findings and conclusions. A useful heuristic is whether a competent reviewer could follow the work without asking the auditor — but the standard itself is about supporting conclusions. Documenting procedures without tying them to conclusions is insufficient.
6

Audit Testing & Sampling Methodology

Objective 6 · tests, sampling & CAATs

Testing produces the evidence behind every conclusion. Choosing the right test, the right sample, and understanding the risk of being wrong is core auditor craft.

Types of tests (rising reliability)

  • Inquiry (lowest reliability; needs corroboration) → observationinspection/examinationre-performance (auditor repeats the control) → analytical procedures.
  • Test of controls verifies a control operates as designed; test of details (substantive) verifies the underlying transactions or balances.

Sampling

  • Statistical sampling uses probability and can be projected to the population (random, systematic, stratified). Non-statistical (judgmental) sampling relies on auditor judgment and cannot be projected (also block and haphazard).
  • Sample size depends on population size, acceptable risk of incorrect acceptance, and the tolerable vs. expected deviation rate.
  • Sampling risk: under-reliance (alpha / Type I — concluding a good control is bad) vs. over-reliance (beta / Type II — concluding a bad control is good).
🔎 In practice

If a sample's deviation rate exceeds the tolerable rate set at planning, the control cannot be relied upon — you report it. You do not keep enlarging the sample until the numbers pass, or lower the tolerance to match the result.

💡 Exam TipBeta risk (over-reliance / Type II) is the more dangerous sampling risk — concluding controls work when they don't. Sampling-risk questions usually hinge on which risk is more consequential to audit quality.

Try it — how much testing does the risk model demand?

Sample size isn't guesswork — it falls out of the audit risk model. Set inherent and control risk and the audit risk you're willing to accept; the model returns the detection risk you can allow, and the sample size needed to earn it. Watch weak controls force you to test more.

Interactive · adjust & explore
Your judgment

Set the risks; the model sizes the test.

Risk assessment
80%
Risk before controls — how error-prone the area is.
50%
Chance controls fail to catch an error. Weaker controls → higher.
5%
Overall risk of a wrong opinion you'll accept.
Sampling parameters
8%
Highest error rate you'd still rely on the control at.
1%
Error rate you actually expect to find.
What the model returns
Risk of material misstatement
Allowable detection risk
Assurance required
Required sample size
Set the risks to size the test.
Sample size vs. control risk

As controls weaken (control risk rises), the detection risk you can accept shrinks — so the sample grows. Your operating point (●) slides along the curve; the curve itself shifts with inherent risk, the audit-risk target, and tolerances. Assumes a large population.

Sample size at your settings Your operating point
🔎 In practice

The numbers are a teaching approximation of attribute sampling — real engagements use ISACA/AICPA tables — but the direction is exam-true: weaker controls and lower tolerance demand more evidence. And note the trap: if expected deviations reach your tolerable rate, no sample size rescues reliance — you report the deficiency, you don't keep sampling until it passes.

7

Audit Evidence Collection

Objective 6 · evidence & CAATs

Audit conclusions must rest on evidence that is both sufficient (enough) and appropriate (relevant and reliable). Reliability depends heavily on where the evidence comes from.

  • Reliability hierarchy (most to least): the auditor's direct observation or re-performance → documentary evidence from third parties → documentary evidence from the organization → oral evidence (inquiry).
  • Collection techniques: document review, interview, observation, walk-through (tracing a transaction end to end), reconciliation, and third-party confirmation.
  • CAATs (Computer-Assisted Audit Techniques): audit software (extract and analyze data), test data (dummy transactions through the live system), Integrated Test Facility (ITF) (a fictitious entity embedded in production), and parallel simulation (auditor re-creates processing logic and compares).
  • ITF vs. parallel simulation — the risk difference: ITF (and test data) push fictitious transactions inside production, which must be removed or reversed or they corrupt real data; parallel simulation re-runs the auditor’s own logic outside production, so it carries no data-corruption risk.
  • Protect the custody and security of confidential evidence obtained during the audit.
🔎 In practice

Test data and ITF deliberately push fictitious transactions through production. If those entries aren't completely removed or reversed when testing ends, they corrupt real data and reporting — a significant risk the auditor owns.

💡 Exam TipTest data and ITF introduce fictitious data into production. The auditor must ensure all fictitious entries are completely removed or reversed before concluding the test — failure to remove test data is a serious risk.
8

Audit Data Analytics

Objective 7 · data analytics

Analytics shift auditing from samples to entire populations — every transaction rather than a subset — dramatically improving coverage and the odds of catching anomalies.

  • Common applications: completeness testing, duplicate detection, gap analysis (missing sequence numbers), outlier/anomaly detection, trend analysis, and Benford's Law (deviations from expected leading-digit frequencies can signal manipulation).
  • Tools: ACL (Galvanize/Diligent), IDEA, Microsoft Excel, Python/R, and Tableau/Power BI for visualization.
  • Analytics are only as good as the data: it must be complete, accurate, and drawn from authoritative sources. Auditors must work from read-only access — DBA or production access is inappropriate.
  • Distinguish continuous auditing (automated testing performed by auditors) from continuous monitoring (automated control monitoring performed by management).
🔎 In practice

Running Benford's Law across an entire expense file can flag manipulated amounts that a 30-item judgmental sample would almost certainly miss — population testing changes what's findable.

💡 Exam TipAn auditor performing analytics needs read-only access to authoritative data. Holding DBA or production access is itself a control weakness — and grants the auditor capabilities that conflict with independence.
9

Reporting & Communication

Objective 8 · findings & communication

A finding only has value if it is communicated clearly and at the right time. A consistent structure makes findings defensible and actionable.

The CRAF finding structure

  • Condition (what was found) · Criteria (the expected standard) · Cause (root cause) · Risk/Effect (consequence) · Recommendation (how to close the gap).

The reporting process

  • Present findings in a draft to management for response before final issuance; management acknowledges each finding with a remediation plan and target date.
  • Report components: scope & objectives, executive summary, detailed findings, management response, and overall conclusion/opinion.
  • Audit opinions: unqualified (clean), qualified (minor exceptions), adverse (material weaknesses), or disclaimer (unable to form an opinion).
  • Critical findings discovered during fieldwork must be escalated immediately — not held for the final report. Significant issues route to the audit committee/board, preserving the audit function's independence.
🔎 In practice

An auditor who uncovers an actively exploitable security hole mid-fieldwork communicates it to management/the audit committee right away. Waiting weeks for the final report would itself be an audit-quality failure.

💡 Exam TipWhen a critical issue surfaces during fieldwork, the correct action is to communicate it immediately to the appropriate level — not wait for the final report. Timing of communication matters.
10

Quality Assurance & Improvement of the Audit Process

The audit function must hold itself to the same scrutiny it applies elsewhere. Quality assurance keeps audit work meeting professional standards and feeds continuous improvement.

  • Internal QA: supervision and workpaper review, engagement quality reviews for high-risk work, and internal peer review.
  • External QA: an independent external quality assessment of the audit function, plus ISACA peer-review programs.
  • Key performance indicators: audit-plan completion rate, average findings per engagement, repeat-finding rate, time from fieldwork to report issuance, and percentage of recommendations implemented on schedule.
  • Use those metrics to refine methodology, resource allocation, and staff development. ISACA's ITAF (IT Assurance Framework) integrates standards, guidelines, and tools into one quality framework.
🔎 In practice

A rising repeat-finding rate tells you recommendations aren't being implemented — a signal that matters to both the audit function's quality program and to management's accountability for remediation.

Scored Knowledge Check

Test your Domain 1 judgment

Ten questions across Planning (1A) and Execution (1B). Select the best answer, then submit for your score and the rationale for every item — including why the trap answers fail. Answer from the auditor's perspective.

Part A — Planning (Domain 1A)

Q1.During audit planning, an IS auditor identifies 12 potential audit subjects: five high-risk, four medium-risk, three low-risk. Resources allow only six engagements. Which approach BEST reflects risk-based planning?

Question 1 options
Correct: B. Risk-based planning concentrates resources on the highest-risk areas first. All five high-risk subjects are included; the remaining slot goes to the next-highest medium subject. Random selection (A) ignores risk; management direction (D) compromises independence. Why the others fall short: A random selection ignores risk entirely; C covering low-risk areas while leaving two high-risk ones unaudited misallocates scarce effort; D hands the auditor’s independent risk judgment to management.

Q2.An IS auditor finds that supervisors verbally approve overtime before timecards are submitted, but no system control enforces this approval. This BEST represents:

Question 2 options
Correct: D. A verbal approval with no system enforcement is a directive control (guidance) at best. The key distinction is enforcement: a directive control communicates the expected behavior (a policy, procedure, or verbal instruction), but only a preventive control actually blocks the act — an enforced approval gate or system control. Here nothing stops unapproved overtime from being entered, so no preventive control exists. It is also not IT-dependent (no IT component) and not detective (it does not identify errors after the fact). Why the others fall short: A nothing enforces the verbal approval, so it isn’t an adequate preventive control; B a verbal sign-off detects nothing after the fact; C no IT-generated output is involved, so it isn’t IT-dependent.

Q3.An organization's external auditor requests the IS auditor's working papers from last year's IT general controls review. The IS auditor should:

Question 3 options
Correct: B. Working papers are the property of the audit organization. Release to third parties, including external auditors, requires authorization. Consulting legal counsel and management is the appropriate first step. Why the others fall short: A releasing privileged work product without authorization is premature; C is overstated — working papers can be shared with proper authorization; D still decides the release unilaterally without consulting.

Q4.Which BEST describes the purpose of a risk-based audit plan compared to a cyclical (rotation-based) plan?

Question 4 options
Correct: B. Risk-based plans prioritize by assessed risk; cyclical plans rotate through entities on a schedule without necessarily considering current risk. Both can be used by internal or external auditors. Why the others fall short: A volume/efficiency isn’t the defining difference; C both approaches apply to internal and external audit alike; D approval authority doesn’t distinguish them.

Q5.During planning, an IS auditor learns the organization recently suffered a major breach in its customer database — a system not in the original plan. The auditor should:

Question 5 options
Correct: B. A significant breach is a material change in the risk profile. The risk-based plan must be updated to incorporate this new high-risk area. Proceeding with the original plan when material risk has emerged violates risk-based principles. Why the others fall short: A rigidly freezing the plan ignores material new risk; C deferring a fresh breach a year leaves a known high risk unexamined; D a limited review under-responds to a major breach.

Part B — Execution (Domain 1B)

Q6.An IS auditor uses audit software to extract and analyze 100% of the prior year's accounts payable transactions. This BEST describes:

Question 6 options
Correct: C. Examining 100% of a population is not sampling at all — it is a complete population analysis. Sampling only occurs when a subset is selected to represent the whole. Why the others fall short: A using a tool doesn’t make it sampling — the whole population was examined; B no sample was drawn, so it isn’t judgmental sampling; D block sampling is still a sample, not a full-population test.

Q7.While testing an automated three-way-match control, an IS auditor processes fictitious purchase orders through the live system. The MOST important follow-up action is to:

Question 7 options
Correct: B. Removing all fictitious test data from production is the most critical post-testing action. Leaving it could corrupt data integrity, trigger false control activity, or affect financial records. Why the others fall short: A reporting while test data pollutes production ignores the integrity risk; C notifying isn’t enough — the data must be removed; D leaving fictitious transactions in production corrupts real records.

Q8.An IS auditor presents draft findings to management three days before issuance. Management disagrees with one finding and offers a technical explanation the auditor hadn't considered. The auditor should:

Question 8 options
Correct: C. The auditor must consider new evidence. If management's explanation is supported and changes the finding, revise it; if it does not change the evidence, the finding stands with management's response documented. Why the others fall short: A refusing to weigh new evidence isn’t objective; B dropping a finding merely because it’s challenged abandons evidence-based judgment; D escalating before evaluating the information skips the auditor’s own analysis.

Q9.During a routine payroll audit, an auditor finds evidence suggesting the CFO is approving fictitious employee payments. The auditor should FIRST:

Question 9 options
Correct: C. Suspected fraud involving senior management requires immediate escalation to the audit committee or board, bypassing the normal management chain. The principle is independence, not just procedure: the suspected party (the CFO) is management, so the normal reporting chain is compromised — the audit committee/board escalation path exists precisely for this scenario, keeping the auditor independent of the people under suspicion. Expanding testing (A) may follow, but only after escalation; waiting for a scheduled report (D) is inappropriate given the severity. Why the others fall short: A expanding scope first delays reporting suspected senior-management fraud; B going through management channels risks alerting a potentially complicit chain; D deferring to the next report is far too slow for suspected fraud.

Q10.After testing user-access recertification, the deviation rate in the sample exceeds the tolerable deviation rate set at planning. The auditor should:

Question 10 options
Correct: B. When sample results exceed the tolerable deviation rate, the control cannot be relied upon. The auditor concludes it is ineffective and reports accordingly. Increasing the sample after a failed test, or adjusting tolerance to match results, are not appropriate responses. Why the others fall short: A re-testing until it passes is result-shopping; C lowering the tolerable rate to match the result rationalizes the failure away; D inquiry adds context but doesn’t undo that the control failed its test.