Audit Interviews: Questioning Techniques for IS Auditors
Master the art of audit interviews with questioning techniques, preparation strategies, and best practices for IS auditors preparing for the CISA exam.
Interviews are one of the primary evidence-gathering techniques available to IS auditors. Effective interviewing requires preparation, structured questioning, and the ability to assess the reliability of responses. CISA candidates should understand interview techniques and their role in the audit process.
The Role of Interviews in IS Auditing
Interviews complement other audit evidence sources such as documentation review, observation, and technical testing. They provide insights into how processes actually operate (as opposed to how they are documented), help auditors understand the reasoning behind control decisions, and can reveal issues that other techniques might miss.
Preparing for Audit Interviews
Thorough preparation is essential for productive interviews. Before conducting an interview, the IS auditor should:
- Review relevant documentation, policies, and prior audit findings
- Understand the interviewee's role and responsibilities
- Prepare a list of questions organized by topic
- Identify specific evidence or documentation to request during the interview
- Schedule the interview at a convenient time and allow adequate duration
- Determine whether the interview should be conducted individually or in a group setting
Types of Questions
Open-Ended Questions
Open-ended questions encourage detailed responses and are useful for understanding processes and gathering context. Examples include:
- "Can you describe how access requests are processed?"
- "What happens when a backup job fails?"
- "How does your team prioritize security incidents?"
Closed-Ended Questions
Closed-ended questions elicit specific, factual answers and are useful for confirming details. Examples include:
- "How many administrators have root access to the database server?"
- "Is the disaster recovery plan tested annually?"
- "When was the last security awareness training session?"
Leading Questions (to Avoid)
Leading questions suggest a desired answer and should be avoided as they compromise the objectivity of audit evidence. For example, "You do review access logs daily, don't you?" pressures the interviewee to confirm the suggested practice.
Probing Questions
Probing questions follow up on initial responses to obtain deeper understanding. They help auditors clarify ambiguous answers and uncover additional details. Examples include:
- "Can you walk me through a specific example?"
- "What would happen if that step were skipped?"
- "How do you handle exceptions to that process?"
Interview Best Practices
- Active listening: Pay attention to what is said and what is not said
- Note-taking: Document responses promptly and accurately
- Corroboration: Validate interview responses with documentary or technical evidence
- Professional demeanor: Maintain objectivity and avoid confrontational approaches
- Follow-up: Send a summary of key points to the interviewee for confirmation
Assessing Interview Evidence
Interview responses are considered less reliable than documentary or observational evidence because they are subjective. IS auditors should corroborate key statements with supporting documentation, system configurations, or independent testing.
CISA Exam Tips
Exam questions may ask about the most appropriate type of question for a given situation. Remember that open-ended questions are generally preferred for initial inquiry, while closed-ended questions are better for confirming specific facts. Always prioritize corroborating interview evidence with independent sources.