CISA Cheat Sheet: Audit Evidence, Controls and Risk
Review CISA control distinctions, evidence checks, recovery objectives and calculation examples before mixed audit practice.
Use this reference to recall a distinction, then explain it in your own words before checking a new scenario. The examples are independent study illustrations; an engagement’s criteria, authority and facts determine the conclusion.
Establish the assertion before choosing the procedure
| Question to settle | Evidence that helps | Common overreach |
|---|---|---|
| Is the control suitably designed? | Required outcome, responsibilities, workflow and coverage of the risk | Treating a missing record as proof the design itself is absent. |
| Did it operate during the period? | Dated execution evidence from the relevant population and period | Treating a current demonstration as evidence for the whole year. |
| Is the report complete? | Reconciliation to an independently supported population, including exclusions | Accepting matching row counts when record identities differ. |
| Are the values accurate? | Recalculation, source support and transformation checks | Assuming completeness proves accuracy. |
| Is an action authorized? | Applicable mandate, approval authority, conditions and validity period | Assuming an exception is invalid merely because it differs from the baseline. |
Evidence is assertion-specific. Inquiry can explain a process and identify records to inspect. It is usually weaker support for repeated operation than corroborated execution evidence. A screenshot establishes what was visible at a point in time, not every change before and after it. Reperformance is persuasive for the operation reproduced, but a poorly chosen sample still limits the conclusion.
Audit, governance and management responsibilities
Management owns business operations, control implementation and risk decisions within delegated authority. Governance bodies oversee direction, accountability and performance. Auditors independently evaluate and communicate; recommending a control does not make the auditor its operator or risk owner.
An audit charter should establish authority, access and reporting responsibilities. For a restricted audit, make the limitation and its effect on assurance visible. Do not quietly replace inaccessible evidence with weaker material and retain the original level of confidence.
| Distinction | Recall cue |
|---|---|
| Inherent vs residual risk | Exposure before considering controls vs exposure remaining after the controls considered. |
| Risk appetite vs tolerance | Broad willingness to take risk vs acceptable variation or limits around objectives. Apply the organization’s actual definitions. |
| Acceptance vs remediation | An authorized decision to retain exposure vs action that changes it. Acknowledging a finding is neither by itself. |
| Policy vs procedure | Required direction or intent vs steps for carrying it out. Supporting standards may define mandatory detail. |
| Preventive vs detective control | Stops or reduces the likelihood of an unwanted event vs identifies it. The same mechanism can have different uses. |
| Compensating control | An alternative that addresses the relevant risk; verify coverage, reliability, timeliness and evidence. |
A control can be documented but badly designed, well designed but inconsistently performed, or effective for one assertion but irrelevant to another. Keep those conclusions separate.
Sampling and data analysis
Start with the population, period and unit: transactions, accounts, changes or control executions. Validate the extraction before relying on analysis. Filters, joins, duplicates, missing time periods and late-arriving records can change what the population means.
For attribute testing, let d be deviations found and n be items tested. The observed sample deviation rate is:
If three of 60 selected approvals are missing, the observed rate is 5%. That is not automatically the population rate or a pass/fail decision. Interpret the result using the sampling method, tolerable deviation and required assurance. Statistical inference needs the method’s uncertainty assessment; a judgmental sample does not acquire statistical precision merely by being large.
Direction matters: tracing from a supported source population to a report tests whether required items reached the report. Vouching from reported items back to source support tests whether the reported items are supported. Neither direction establishes every financial or operational assertion on its own.
Acquisition, changes and conversion
| Stage | Useful audit focus |
|---|---|
| Business case | A supported need, realistic alternatives, benefit assumptions and accountable owners. |
| Requirements and design | Traceable business/control requirements, including security, privacy and operational needs. |
| Testing | Expected outcomes, representative cases, independent assessment where appropriate and recorded defects. |
| Conversion | Source-to-target identity, values, relationships, exceptions and reconciled totals. |
| Release | Authorized changes, separation of incompatible duties, rollback and operational readiness. |
| Post-implementation | Achieved benefits, outstanding defects, control operation and lessons for later work. |
A successful deployment only shows that deployment completed. It does not prove that migrated data is complete or that users can perform the intended business process. An emergency change route should still provide defined authority, records and the retrospective review required by that route.
Recovery and availability
RTO is the targeted elapsed time to restore the relevant service or activity after disruption. RPO identifies the point to which data must be recoverable, expressing tolerable data loss in time. A backup schedule is not proof either objective will be met.
Example: a disruption occurs at 14:00, the latest usable recovery point is 13:40, and the validated service returns at 15:10. The demonstrated loss window is 20 minutes and the recovery elapsed time is 70 minutes. Against an RPO of 15 minutes and RTO of 90 minutes, recovery time meets the target but data loss does not. Use the scenario’s defined start and completion events; restoring a server alone may not restore the business service.
\[ A=\frac{E-D}{E}\times100\% \]Here E is eligible time and D is counted downtime, in the same units.
With a 10,000-minute window, 100 minutes of contractually excluded maintenance and 30 minutes of counted downtime, eligible time is 9,900 minutes. Availability is approximately 99.697%. Apply the same exclusion rules to numerator and denominator; the agreement determines which events qualify.
A business impact analysis identifies consequences of disruption, priorities and dependencies. A recovery test then needs evidence that people, facilities, identity, data, interfaces and critical suppliers can support those priorities. Replication can rapidly copy corruption; an isolated recoverable backup addresses a different risk.
Information protection and third parties
| Control question | Evidence to connect |
|---|---|
| Is access appropriate? | Authoritative role/status, business need, approval, actual entitlement and timely removal. |
| Are privileged actions attributable? | Individual authentication or reliable attribution, session/activity records, protection and review of logs. |
| Does encryption address this exposure? | Data state, endpoints, key access, rotation/recovery and which actors still see plaintext. |
| Can an incident be investigated? | Relevant logging, synchronized time, retention, integrity and evidence-handling records. |
| Does external assurance cover our reliance? | Correct service, period, controls, exceptions, subservice treatment and customer responsibilities. |
A report describing controls at a date and one reporting tests of operation over a period answer different questions. A service provider’s later statement can help bridge a reporting gap, but material changes or contrary evidence may require additional work. Read scope and exclusions before relying on a reassuring report title.
For cloud and outsourced services, determine who performs each control and who must verify the result. Outsourcing operation does not eliminate the customer’s responsibility to understand and oversee its business risk.
Final check before selecting an answer
State the required judgment in one sentence. Then ask whether the option answers that judgment with evidence available to the stated role. “Business risk,” “policy,” “management” and “more testing” are not universal winning words. A technically sound action can be premature, outside the role or directed at the wrong assertion.
Continue with worked CISA scenarios or the free practice exam .