exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 104 discussion

Actual exam question from Isaca's CISA
Question #: 104
Topic #: 1
[All CISA Questions]

Due to system limitations, segregation of duties (SoD) cannot be enforced in an accounts payable system. Which of the following is the IS auditor's BEST recommendation for a compensating control?

  • A. Require written authorization for all payment transactions.
  • B. Review payment transaction history.
  • C. Reconcile payment transactions with invoices.
  • D. Restrict payment authorization to senior staff members.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pauloludele
Highly Voted 2 years, 9 months ago
The correct answer is C because there is no dual control due to system limitation, the only compensating control here is to reconcile each transaction with the invoice inorder to ensure the accuracy of the transaction processed.
upvoted 10 times
...
Greens
Most Recent 3 weeks, 3 days ago
Selected Answer: A
When Segregation of Duties (SoD) cannot be enforced due to system limitations, the IS auditor must recommend a compensating control that reduces the risk of unauthorized or fraudulent payments. Written authorization for all payment transactions provides a formal approval process that adds a layer of oversight, helping to: Prevent unauthorized payments, Provide audit trails, and Ensure accountability. This control directly addresses the risk arising from the lack of SoD. Why not the others? B. Review payment transaction history ➤ This is a detective control and usually performed after transactions, which is less effective than preventive controls. C. Reconcile payment transactions with invoices ➤ Important but also detective in nature; it doesn’t prevent unauthorized payments upfront. D. Restrict payment authorization to senior staff members ➤ Restricting authorization is good but without a formal written approval process, it may lack accountability and evidence.
upvoted 1 times
...
cisaisff
3 months ago
Selected Answer: B
In system environments where SoD is not possible, Independent and periodic review of payment history is the most realistic and effective compensation control. This is useful for detecting user abuse and curbing the occurrence of fraud.
upvoted 1 times
...
IFBBPROSALCEDO
3 months, 3 weeks ago
Selected Answer: C
When segregation of duties can't be enforced, the best compensating control is implementing robust and regular reconciliations (option C) to independently verify the accuracy, validity, and authorization of accounts payable transactions.
upvoted 1 times
...
TranquiRelax
6 months ago
Selected Answer: A
Reconciliation is typically a post-transaction control and might not catch fraud or errors in the payment process before the transaction is authorized. Hence the answer is A.
upvoted 1 times
...
NoKev
10 months, 3 weeks ago
Selected Answer: A
I go with A. It says there is a system limitation, meaning they will have to use what they already have. Can't assign more work or responsibility since they got no people. Hence, best option is to create a authorization system in between.
upvoted 3 times
...
Veexx
11 months, 2 weeks ago
Why not A?
upvoted 1 times
...
a84n
1 year, 2 months ago
Selected Answer: C
Answer: C
upvoted 2 times
...
5b56aae
1 year, 2 months ago
Selected Answer: A
A is preventive and compensating control
upvoted 2 times
...
OD1N
1 year, 7 months ago
B>????????
upvoted 2 times
CISA2021
1 year, 5 months ago
B) is a detectiv control, not a compensating control
upvoted 2 times
...
...
MunaM
2 years, 10 months ago
answer should be D because it will have the dual control
upvoted 2 times
abeedfarooqui86
1 year, 11 months ago
They mentioned that SoD cannot be carried out, hece D cannot be the answer.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...