by MTC Group, LLC
CISA D1: Information System Auditing Process
CISA Domain 1 (18% weight) covers how an IS audit is planned, performed, and reported: audit standards (ISACA's IT Audit Framework, ITAF), guidelines and codes of ethics, risk-based audit planning, control types, testing and sampling, evidence collection, data analytics, and communicating results. The auditor's point of view set up here carries into every other CISA domain, so it pays to master it first.
The biggest mindset shift for CISSP and CISM holders: on CISA, you are the auditor, not the implementer. The auditor evaluates controls, gathers evidence, reports findings, and recommends improvements. A useful habit is to be wary of any answer choice that has the auditor designing, fixing, or operating a control, because auditing an activity you were responsible for impairs objectivity and independence from management's responsibilities.
ITAF and the ISACA Code of Professional Ethics
ISACA's IT Audit Framework (ITAF), whose newest edition is the 5th, establishes standards that address IT audit and assurance practitioners' roles and responsibilities, ethics, expected professional behavior, and required knowledge and skills. It also defines IT audit and assurance terms and gives guidance and techniques for planning, performing and reporting engagements. Alongside it, ISACA's Code of Professional Ethics requires members and certification holders to perform their duties with objectivity, due diligence and professional care in accordance with professional standards, and to keep information obtained in their work confidential unless disclosure is required by legal authority.
Audit risk model
Audit risk (the risk of reaching an incorrect conclusion) has three components: inherent risk (susceptibility to material misstatement before considering controls), control risk (the chance that internal control fails to prevent or detect it on a timely basis) and detection risk (the chance the auditor's own procedures miss it). Inherent and control risk relate to the auditee and its controls, and the auditor assesses them; the auditor reduces detection risk through the nature, timing, and extent of substantive procedures, and the higher the risk of material misstatement, the lower detection risk must be.
Risk-based audit planning
Audit effort goes to the areas of highest risk to the organization, not evenly across every system or on a fixed rotation. The audit plan rests on a documented assessment of the organization's strategies, objectives and risks, and each engagement starts with understanding the activity under review and its risks; only then are audit objectives, scope, and procedures set.
Evidence reliability
Evidence is more reliable when it comes from a knowledgeable source independent of the auditee, when the auditor obtains it directly (observation, reperformance, recalculation) rather than indirectly, and when it comes from original documents rather than copies. A system report the auditor ran personally beats a spreadsheet the auditee prepared.
Control self-assessment (CSA)
A process in which management and staff at all levels identify and evaluate the risks and controls in their own business areas, often with an auditor or risk manager acting as facilitator. Self-assessment is the organization's own oversight of its controls, carried out by people within the area, and responsibility for it is shared across personnel. Independent assessment of the control system's design and performance is what internal and external audit provide, so a CSA result is management's own view, not an independent audit conclusion.
CAATs and data analytics
Computer-assisted audit techniques (generalized audit software, test data, embedded audit modules and other continuous auditing tools, data analytics) let the auditor test an entire population or audit continuously instead of sampling. Before relying on data produced by the auditee, the auditor must test its accuracy and completeness (or the controls over it).
Reporting and follow-up
Findings and recommendations are discussed with the auditee's management before the report is finalized, but the internal audit function must be free from interference when communicating results: management pressuring auditors to suppress or change findings is a situation that impairs independence. Management is responsible for completing corrective action; the auditor confirms that it was implemented. If the chief audit executive concludes that management has accepted a risk that exceeds the organization's risk appetite or tolerance, the matter is discussed with senior management and, if unresolved, escalated to the board rather than dropped; resolving the risk itself is not the chief audit executive's job.
Compliance testing vs. substantive testing
Compliance tests check whether a control is operating effectively (were purchase orders approved before payment?). Substantive tests check the completeness, accuracy or existence of the actual data or transactions (are the recorded amounts correct?). Weak controls found in compliance testing call for more substantive testing, not less.
Attribute sampling vs. variable sampling
Attribute sampling looks at the presence or absence of a characteristic (did a control fail? a yes/no per item) and pairs with tests of controls, where the auditor sets a tolerable rate of deviations. Variable sampling estimates a monetary or quantitative value (total misstatement in a balance) and pairs with substantive testing. Discovery sampling is a form of attribute sampling.
Audit charter vs. engagement letter
The audit charter establishes the internal audit function's overall purpose, authority, and responsibility, and is approved by those charged with governance (the board or audit committee). An engagement letter defines the auditor's responsibility, authority and accountability for one specific assignment.
Recommend vs. implement
The auditor recommends; management implements. An answer where the auditor writes the fix, configures the control, or takes over a process is an independence problem, even if it would work: auditors must not assess activities they were responsible for. The auditor's role is to report the issue to the appropriate level of management.
- [1]
- [2]
- [3]
- [4]
- [5]
- [6]
- [7]
- [8]
- [9]
- [10]
- [11]
- [12]
- [13]
- [14]
- [15]
- [16]
- [17]
- [18]
- [19]
- [20]
- [21]
- [22]
- [23]
- [24]
- [25]
- [26]
- [27]
- [28]
Practice D1 questions with instant feedback, free to start, no card required.
Start Free© 2026 MTC Group, LLC. All rights reserved. InfoSec ExamPrep™ and the InfoSec ExamPrep logo are trademarks of MTC Group, LLC.
For personal exam preparation only. Printed from examprep.mtcgroupllc.com.