CISa EXAM PREP
CONCISE STUDY SERIES
DOMAIN 1B
Information Systems Auditing Process
Covers every topic
on exam syllabus
with Pete Zerger vCISO, CISSP, MVP
About the exam
Based on the ISACA Certification Guide, here are the key details for
the CISA (Certified Information Security Auditor) exam:
Before April 15, 2024 After April 15, 2024
DOMAINS Weight
CAT Linear CAT Linear
1. Information Systems Auditing Process 18%
2. Governance & Management of IT
4 hours 6 hours 3 hours18% 6 hours
3. Information Systems Acquisition,
12%
Development, and Data Conversion
125 - 175 250
4. Information Systems Operations &
100-150 225
26%
Business Resilience
5. Protection of Information Assets 26%
About this series
The CISA consists of
5 Domains 1 2 3 4 5
Each domain includes
1A,1B 2A,2B 3A,3B 4A,4B 5A,5B
2 Sections
10 installments in the series
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED LIVE QUIZ VIDEO
READING (or flashcards) CONTENT
PRACTICE POWERPOINT
EXAMS REVIEW
Mix, match, and repeat based on your preferences
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED LIVE QUIZ VIDEO
READING (or flashcards) CONTENT
PRACTICE POWERPOINT
EXAMS REVIEW
My preferred order
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED LIVE QUIZ VIDEO
READING (or flashcards) CONTENT
PRACTICE POWERPOINT
EXAMS REVIEW
My preferred order
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED LIVE QUIZ VIDEO
READING (or flashcards) CONTENT
PRACTICE POWERPOINT
EXAMS REVIEW
Course PDFs can help here!
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED LIVE QUIZ VIDEO
READING (or flashcards) CONTENT
PRACTICE POWERPOINT
EXAMS REVIEW
Practice time management in these sessions
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED LIVE QUIZ VIDEO
READING (or flashcards) CONTENT
PRACTICE POWERPOINT
EXAMS REVIEW
For closing knowledge gaps, not cover-to-cover reading
Exam prep strategy
Research shows everyone benefits from a variety of sources!
TARGETED LIVE QUIZ VIDEO
READING (or flashcards) CONTENT
PRACTICE POWERPOINT
EXAMS REVIEW
Multiple resources of each type are a GREAT idea!
Coming September 30th, 2025!
✓ 300+ pages of clear, focused
explanations
✓ Covers every topic on the
ISACA CISA exam syllabus
✓ Dozens of full-color diagrams
and reference tables
✓ Distills the “what, when, and why”
of concepts and technologies
✓ Priced to be accessible to all
Register to be notified at [Link]
HOW
to best use the
PRACTICE quizzes
to assess your
EXAM readiness?
Time management
On exam day, time management (the time you spend
per-question) should be second nature, automatic.
On this exam you will have:
- 4 hours to complete 150 questions
- That’s 90 seconds/question
[Link]
There are free timers available to help
[Link]
practice your time management
D O M A I N 1 : INFO SYSTEMS AUDITING PROCESS
B - EXECUTION
1 Audit Project Management
2 Sampling Methodology
3 Audit Evidence Collection Techniques
4 Data Analytics
5 Reporting and Communication Techniques
D O M A I N 1 : INFO SYSTEMS AUDITING PROCESS
B - EXECUTION
1 Audit Project Management
2 Sampling Methodology
3 Audit Evidence Collection Techniques
4 Data Analytics
5 Reporting and Communication Techniques
D O M A I N 1 : INFO SYSTEMS AUDITING PROCESS
B - EXECUTION
1 Audit Project Management
2 Sampling Methodology
3 Audit Evidence Collection Techniques
4 Data Analytics
5 Reporting and Communication Techniques
1B1: The Audit Execution Lifecycle
A Structured, Repeatable Process
Process Flow:
1. Define Scope & Objectives
2. Gather Evidence
3. Evaluate Strengths & Weaknesses
4. Form Conclusions
5. Prepare Report
6. Follow-Up
Key Takeaway: An effective audit is
managed like a formal project.
1B1: The THREE PHASES of an IS Audit
A Three-Phase Framework
1. Planning Phase
Determine Subject, Define Objective, Set Scope, Pre-audit
Planning, Determine Procedures.
2. Fieldwork & Documentation Phase:
Acquire Data, Test Controls, Discover & Validate Issues,
Document Results.
3. Reporting Phase:
Gather Requirements, Draft Report, Issue Report, Follow-up.
1B1: Fieldwork & Documentation Phase
This is the “doing” phase. Key activities include:
Acquire Data:
Using advance request lists; secure collection methods
(e.g., file share, GRC tools).
Test Controls:
Applying techniques like interviews, observation, and inspection.
This may require sampling.
Discover & Validate Issues:
Identifying deviations from expected outcome. (e.g., policy requirements)
These are the basis for your findings.
Document Results:
Recording every test, observation, and piece of evidence in work
papers per organizational standards.
1B1: Audit Programs & Work Papers
Audit Program:
A step-by-step set of instructions.
It is the "recipe" for the audit.
Purpose: Formal documentation, repeatability, and meeting
professional standards.
Work Papers:
The bridge between the audit objectives and the final report.
Must provide clear traceability from a finding back to the evidence.
Must be secured and retained based on legal and organizational
requirements.
1B1: The Auditor's Responsibility Regarding Fraud
Management's Responsibility:
To establish, implement, and maintain internal controls to
deter and detect fraud.
Auditor's Responsibility:
To exercise due professional care.
To be alert to opportunities or indicators of fraud
(professional skepticism).
To have knowledge of common fraud indicators.
Auditor's Action:
If fraud is suspected, communicate the need for a detailed
investigation to the appropriate authorities.
e.g., audit management, legal counsel
1B1: Modern Approaches: Agile Auditing
Traditional (Waterfall) Audit: Regulatory compliance,
large-scale system audits
Rigid, sequential phases
Plan → Fieldwork → Report
Agile Audit: Continuous or IT operations audits
Iterative, collaborative, and responsive to change.
Blurs the lines between planning and fieldwork.
Focuses on:
✓ Individuals and interactions over processes and tools.
✓ Customer (auditee) collaboration over contract negotiation.
✓ Responding to change over following a rigid plan.
Conceptually, it is similar to Agile development in many respects
Agile development model
SPRINT SPRINT
PLANNING PLANNING
DEMONSTRATION DEVELOPMENT DEMONSTRATION DEVELOPMENT
TESTING TESTING
Sprint 1 Sprint 2
1B1: Key Benefits of Agile Auditing
Key characteristics and benefits of Agile Auditing
Reduced Planning Time: Sprints condense planning from
months to weeks or even days.
Streamlined Engagements: Planning, fieldwork, and reporting
phases are combined into a single cohesive engagement.
Direct Customer Collaboration: The auditee is part of the
process, often participating in daily "scrum" meetings.
Flexible Scope: Allows for real-time adjustments as new
information is discovered.
Real-time Assurance: Findings are communicated as they
are discovered, not held for the final report.
D O M A I N 1 : INFO SYSTEMS AUDITING PROCESS
B - EXECUTION
1 Audit Project Management
2 Sampling Methodology
3 Audit Evidence Collection Techniques
4 Data Analytics
5 Reporting and Communication Techniques
D O M A I N 1 : INFO SYSTEMS AUDITING PROCESS
B - EXECUTION
1 Audit Project Management
2 Sampling Methodology
3 Audit Evidence Collection Techniques
4 Data Analytics
5 Reporting and Communication Techniques
1B2: The Rationale for Sampling
Why Sample?
Time and cost considerations often preclude a 100%
verification of all transactions.
Goal: To infer characteristics about a whole population
based on a representative Sample.
Two Main Purposes of Audit Testing:
Compliance Testing (Test of Controls):
Is the control working as designed?
Substantive Testing (Test of Details):
Are the data and transactions accurate and valid?
1B2: Compliance vs. Substantive Testing
Compliance Testing:
Question: Are controls being applied consistently and
effectively?
Example: Selecting 30 change requests to verify each has a
manager's approval signature.
Focus: The process.
Substantive Testing:
Question: Are there monetary errors or data integrity issues
in the final data?
Example: Recalculating interest on a sample of 50 loans to
verify the accuracy of the total interest income reported.
Focus: The outcome or data.
1B2: The Inverse Relationship
The strength of an organization's internal controls directly impacts
the amount of detailed testing an auditor needs to do.
If Compliance Testing shows
Strength of
controls
controls are strong and reliable:
The auditor can justify reducing the
amount of Substantive Testing.
If Compliance Testing shows
controls are weak or non-existent:
Level of
substantive The auditor must increase the amount
testing of Substantive Testing to compensate.
1B2: The Inverse Relationship
The strength of an organization's internal controls directly impacts
the amount of detailed testing an auditor needs to do.
If Compliance Testing shows
controls are strong and reliable:
Strength of
controls The auditor can justify reducing the
amount of Substantive Testing.
If Compliance Testing shows
Level of controls are weak or non-existent:
substantive
testing The auditor must increase the amount
of Substantive Testing to compensate.
1B2: Statistical vs. Nonstatistical Sampling
Statistical Sampling:
Objective, uses the mathematical laws of probability.
Allows for calculation of sample size and evaluation of results.
Key Benefit: Allows the auditor to state conclusions
with a specific confidence level
(e.g., "We are 95% confident that the error rate is less than 2%").
Results are quantifiable and projectable.
Nonstatistical (Judgmental) Sampling:
Subjective, based on the auditor's experience and judgment.
Auditor selects items they deem most risky or material.
Key Drawback: The results cannot be mathematically
projected to the entire population.
1B2: Decoding Statistical Sampling: Key Terminology
Confidence Coefficient:
The probability that the sample is a true representation (e.g., 95%).
Higher confidence = larger sample size.
Level of Risk (formula):
1 - Confidence Coefficient (e.g., for a 95% CC, risk is 5%).
Precision:
The acceptable range of error. (e.g., +/−3%, +/− $500)
Smaller (tighter) precision = larger sample size.
Tolerable Error Rate: The maximum error rate acceptable before the
control is considered ineffective.
Expected Error Rate: An estimate of the errors you think you'll find.
Higher expected error rate = larger sample size.
1B2: Deeper Dive: Key Sampling Methods
You don't need to be a sampling expert, but you should be
conceptually familiar with key sampling methods for the exam
Attribute Sampling It answers, "how many?"
Used in compliance testing to determine the rate of occurrence of a specific
characteristic (e.g., the percentage of change requests with proper approval).
Stop-or-Go Sampling
An efficient form of attribute sampling used when few errors are expected.
It allows the audit test to be stopped as soon as sufficient assurance is
achieved, saving time.
Discovery Sampling It's used for "zero tolerance" issues.
A specialized technique used to detect even a single instance of a critical
event, such as fraud or a major control circumvention.
1B2: Deeper Dive: Key Sampling Methods
You don't need to be a sampling expert, but you should be
conceptually familiar with key sampling methods for the exam
Variable Sampling: It answers "how much?"
Used in substantive testing to estimate a numerical value, such as a
monetary amount or quantity
(e.g., the total dollar value of inventory errors)
Stratified Mean Per Unit:
A type of variable sampling where the population is first divided into
subgroups (strata) to reduce variability AND
Allows for a smaller, more efficient sample size.
Judgmental Sampling: When results cannot be mathematically projected.
A nonstatistical method where the auditor uses their professional experience
to select items they believe are most risky or significant.
1B2: Deeper Dive: Key Sampling Methods
Sampling Primary Use Case
Type Key Characteristic / Exam Keyword
Method (Testing Type)
Attribute Answers "How many?" or "What percentage?"
Statistical Compliance Testing
Sampling (e.g., % of users with excess access).
Stop-or-Go Used when very few errors are expected;
Statistical Compliance Testing
Sampling allows stopping early to save time.
Used to find even one example of a critical
Discovery
Statistical Compliance Testing deviation (e.g., fraud). Keyword: "zero
Sampling
tolerance".
Variable Estimates a monetary value or quantity (e.g.,
Statistical Substantive Testing
Sampling total value of inventory misstatement).
Divides population into groups (strata) first to
Stratified
Statistical Substantive Testing reduce sample size. Used for varied
Mean Per Unit
populations.
Judgmental Compliance or Auditor uses professional judgment to select
Nonstatistical
Sampling Substantive specific high-risk items. Not projectable.
1B2: Deeper Dive: Key Sampling Methods
Sampling Primary Use Case
Type Key Characteristic / Exam Keyword
Method (Testing Type)
Attribute Answers "How many?" or "What percentage?"
Statistical Compliance Testing
Sampling (e.g., % of users with excess access).
Stop-or-Go Used when very few errors are expected;
Statistical Compliance Testing
Sampling allows stopping early to save time.
Used to find even one example of a critical
Discovery
Statistical Compliance Testing deviation (e.g., fraud). Keyword: "zero
Sampling
tolerance".
Variable Estimates a monetary value or quantity (e.g.,
Statistical Substantive Testing
Sampling total value of inventory misstatement).
Divides population into groups (strata) first to
Stratified
Statistical Substantive Testing reduce sample size. Used for varied
Mean Per Unit
populations.
Judgmental Compliance or Auditor uses professional judgment to select
Nonstatistical
Sampling Substantive specific high-risk items. Not projectable.
1B2: Deeper Dive: Key Sampling Methods
Sampling Primary Use Case
Type Key Characteristic / Exam Keyword
Method (Testing Type)
Attribute Answers "How many?" or "What percentage?"
Statistical Compliance Testing
Sampling (e.g., % of users with excess access).
Stop-or-Go Used when very few errors are expected;
Statistical Compliance Testing
Sampling allows stopping early to save time.
Used to find even one example of a critical
Discovery
Statistical Compliance Testing deviation (e.g., fraud). Keyword: "zero
Sampling
tolerance".
Variable Estimates a monetary value or quantity (e.g.,
Statistical Substantive Testing
Sampling total value of inventory misstatement).
Divides population into groups (strata) first to
Stratified
Statistical Substantive Testing reduce sample size. Used for varied
Mean Per Unit
populations.
Judgmental Compliance or Auditor uses professional judgment to select
Nonstatistical
Sampling Substantive specific high-risk items. Not projectable.
1B2: Compliance vs. Substantive Testing
Compliance Testing:
Question: Are controls being applied consistently and
effectively?
Example: Selecting 30 change requests to verify each has a
manager's approval signature.
Focus: The process.
Substantive Testing:
Question: Are there monetary errors or data integrity issues
in the final data?
Example: Recalculating interest on a sample of 50 loans to
verify the accuracy of the total interest income reported.
Focus: The outcome or data.
D O M A I N 1 : INFO SYSTEMS AUDITING PROCESS
B - EXECUTION
1 Audit Project Management
2 Sampling Methodology
3 Audit Evidence Collection Techniques
4 Data Analytics
5 Reporting and Communication Techniques
D O M A I N 1 : INFO SYSTEMS AUDITING PROCESS
B - EXECUTION
1 Audit Project Management
2 Sampling Methodology
3 Audit Evidence Collection Techniques
4 Data Analytics
5 Reporting and Communication Techniques
1B3: Defining Audit Evidence
What is Audit Evidence?
Any information used by the auditor to determine whether the entity
or data being audited follows the established criteria or objectives.
The Three Pillars of Quality Evidence:
Evidence must be...
✓ Sufficient: Is there enough of it? (Quantity)
✓ Relevant: Does it relate directly to the audit objective? (Quality)
✓ Competent / Reliable: Can it be trusted? (Quality)
1B3: Determinants of Evidence Reliability
HIGHER A Hierarchy of Reliability (Most to Least Reliable):
1) Direct observation and reperformance by the IS auditor.
2) Evidence from an independent, qualified third party.
RELIABILITY
(e.g., a bank confirmation, SOC report).
3) Evidence from a well-controlled internal process.
(e.g., a system-generated log from a secure system)
4) Documentary evidence provided by the auditee.
(e.g., a manually created list, a screenshot)
5) Verbal statements from the auditee.
Least Reliable - must always be corroborated
LOWER
1B3: Evidence Gathering Techniques
Reviewing
Organization structures, policies, standards, and system
documentation.
Interviewing
Conducting structured inquiries with appropriate personnel.
Observing
Watching processes and employees perform their duties in real-time.
Reperformance
Independently executing a control procedure to verify the result.
Walk-throughs
Tracing a single transaction from initiation to completion to
understand the entire process and its controls.
1B3: Scenario-Based Application
Audit Objective:
Verify that terminated user accounts are disabled in a timely manner.
Which technique provides the BEST evidence?
A. Interviewing the HR manager about the off-boarding process.
B. Reviewing the company's official user de-provisioning policy
document.
C. Observing a help desk technician disable one user's account.
D. Obtaining the list of employees terminated last month from HR and
independently inspecting their account status in Active Directory.
D O M A I N 1 : INFO SYSTEMS AUDITING PROCESS
B - EXECUTION
1 Audit Project Management
2 Sampling Methodology
3 Audit Evidence Collection Techniques
4 Data Analytics
5 Reporting and Communication Techniques
D O M A I N 1 : INFO SYSTEMS AUDITING PROCESS
B - EXECUTION
1 Audit Project Management
2 Sampling Methodology
3 Audit Evidence Collection Techniques
4 Data Analytics
5 Reporting and Communication Techniques
1B4: Data Analytics
Leveraging Data Analytics in the IS Audit:
Allows the auditor to test full data sets (100%) instead of just samples.
Common Use Cases:
Identify exceptions or potential fraud
(e.g., searching for duplicate payments across all vendors).
Assess control effectiveness
(e.g., analyzing all user access rights against approved job roles).
Conduct enterprise-wide risk assessments.
Identify business process improvements and inefficiencies.
1B4: Computer-Assisted Audit Techniques (CAATs)
What is a CAAT?
Any automated tool used by an auditor to make the audit process
more efficient and effective.
Key Example: Generalized Audit Software (GAS)
– Purpose-built software for auditors. (e.g., ACL, IDEA, Arbutus).
– Can directly read and analyze data from various database
platforms, flat-file systems, and ERPs.
– Performs functions like file access, data selection, statistical
analysis, duplicate checking, and gap detection.
Other CAATs: Utility software, test data, vulnerability
scanners, penetration testing tools.
1B4: Continuous Auditing vs. Continuous Monitoring:
Continuous Monitoring:
Who: Management / The Business.
What: An internal control process, performed by management, to
observe the performance of systems and controls in real-time.
Example: An automated alert in the identity management system that
fires when a user is granted conflicting permissions (a SoD violation).
Continuous Auditing:
Who: The Auditor.
What: An independent and objective process to perform tests and
assessments on a continuous or near-continuous basis.
Example: The auditor's system independently queries the user access
list daily to identify and report on any conflicting permissions.
1B4: The Five Techniques for Continuous Auditing
Technique Description Complexity Exam Keyword / Use Case
SCARF (System
Control Audit Review Audit software embedded into the "Embedded"; Regular
File) / EAM host application to select and log Very High processing cannot be
(Embedded Audit transactions meeting certain criteria. interrupted.
Module)
Takes "pictures" of a transaction as it
"Audit trail"; Tracing the
Snapshots flows through the system, creating Medium
path of a transaction.
an audit trail.
"Red flags" in the system that call the "Real-time notification";
Audit Hooks auditor's attention to specific, Low Only select transactions
unusual transactions in real-time. need examination.
A "dummy" company or division is "Dummy entity"; Testing
ITF (Integrated
set up in the live production system High with test data in the live
Test Facility)
to process test transactions. environment.
CIS (Continuous The system simulates processing for "Simulates"; Transactions
and Intermittent transactions that meet certain Medium meeting specific criteria
Simulation) criteria and audits them in parallel. need examination.
1B4: The Role of AI and ML in Auditing
AI and ML are an evolution of traditional CAATs.
Capabilities:
Automate tedious manual processes
(e.g., reviewing contracts, analyzing complex log files).
Identify complex patterns and anomalies that traditional rules-based
CAATs might miss.
Continuous Auditing:
Inadequate testing of the AI can produce questionable results.
Training data fed to the AI must be correct, complete, and unbiased.
The tendency to "trust the machine" must be balanced with
professional skepticism and human judgment.
D O M A I N 1 : INFO SYSTEMS AUDITING PROCESS
B - EXECUTION
1 Audit Project Management
2 Sampling Methodology
3 Audit Evidence Collection Techniques
4 Data Analytics
5 Reporting and Communication Techniques
D O M A I N 1 : INFO SYSTEMS AUDITING PROCESS
B - EXECUTION
1 Audit Project Management
2 Sampling Methodology
3 Audit Evidence Collection Techniques
4 Data Analytics
5 Reporting and Communication Techniques
1B5: Reporting and Communication Techniques
The Final and Most Critical Stage
Effective communication is what gives the audit its value. An audit with
brilliant fieldwork but a poor report is a failed audit.
Key Skills for the Auditor:
✓ Facilitation
✓ Negotiation
✓ Conflict Resolution
The Goal:
Not to "win" an argument, but to persuade management to take
corrective action and improve the control environment.
1B5: Reporting and Communication Techniques
The Exit Interview
A formal meeting with auditee management at the
conclusion of fieldwork.
Key Objectives:
Ensure the factual accuracy of all findings before they
are written.
Discuss recommendations and ensure they are
realistic, practical, and cost-effective.
Negotiate and agree upon implementation dates for
corrective actions.
The "No Surprises" Rule: Avoids blindsiding
management in the final report.
1B5: Anatomy of an Audit Report
The key elements of an audit report
are important knowledge for the exam
1. Introduction:
Audit Objectives, Scope, Limitations, Period of Coverage.
2. Overall Conclusion & Opinion:
The "bottom line" - are the controls adequate to meet the
objectives?
3. Reservations/Qualifications:
Any limitations that affected the audit.
1B5: Anatomy of an Audit Report
The key elements of an audit report
are important knowledge for the exam.
4. Detailed Findings & Recommendations:
For each finding, include:
o Condition: What is the weakness? ("What is")
o Criteria: What should it be? (The standard, policy, or best
practice)
o Cause: Why did it happen? (The root cause)
o Effect / Risk: What is the business impact?
Why should management care?
o Recommendation: How to fix it.
1B5: Materiality and Follow-Up
Materiality
The relative importance of a finding.
It is a professional judgment of the finding's potential effect on
the business if not corrected.
Not all findings are equal.
Follow-Up Activities
The audit is not over when the report is issued.
The audit function must include a process to ensure follow up.
This is necessary to determine if management has implemented
the agreed-upon corrective actions in a timely manner.
INSIDE CLOUD
THANKS
F O R W A T C H I N G!