Concept and mechanism
An audit begins with an assurance question, not a tool list. Clarify mandate, objectives, criteria, scope, period, and access authority. Criteria may come from policy, contract, or applicable obligation; identify them before concluding that a deviation exists. Plan work proportionate to risk and business consequences. A recently changed settlement service may justify revisiting approved priority even if another system has gone longer without audit. Preserve the approval process for plan changes. Management remains responsible for decisions and controls; audit evaluates and communicates without automatically taking over operations.
Guided application
Independence and competence differ. If you helped implement the pipeline, disclose that involvement before signing independent assurance over it. Your knowledge may be used as bounded support with genuinely independent leadership and conclusion; formal signature without review is insufficient. With external specialists, check competence, conflicts, authorization, and information protection. An interview clarifies a process but does not demonstrate every execution across six months. Choose procedures matching the temporal objective. The current CISA outline is the August 2024 outline. ISACA currently lists ITAF 5; this course uses public guidance and does not invent clause numbers from full text that was not consulted.
A review of January–June approvals needs evidence for that period; September configuration does not automatically reconstruct decisions.
Common pitfalls
Technical experience as independence; tool as objective; possible access as authority.
Related topics: Evidence, samples, and conclusions · Governance, resources, and suppliers
Start by defining what will be demonstrated, within which scope, and with what independence.
Reference: Code of Professional Ethics · CISA outline effective August 1, 2024