CISA Domain 1 Study Guide: Key Concepts and Formulas
A comprehensive study guide covering key concepts, formulas, and focus areas for CISA Domain 1: Information Systems Auditing Process.
Domain 1 of the CISA exam covers the Information Systems Auditing Process and accounts for approximately 21% of the exam. This study guide summarizes the key concepts, methodologies, and focus areas that every CISA candidate should master.
Audit Planning and Management
Audit planning is the foundation of an effective IS audit. Key concepts include:
- Risk-based audit planning: Prioritize audit engagements based on risk assessment results, focusing resources on the highest-risk areas
- Audit universe: The complete inventory of auditable entities within the organization
- Annual audit plan: A schedule of planned audits, approved by the audit committee, that allocates resources across the audit universe
- Engagement planning: Detailed planning for individual audits, including scope, objectives, timing, and resource requirements
ISACA Audit Standards
IS auditors must follow ISACA's IS Audit and Assurance Standards, which include:
- General standards: Independence, professional competence, due professional care
- Performance standards: Planning, evidence, reporting
- Reporting standards: Report content, format, and distribution
Evidence and Sampling
Understanding evidence quality and sampling methods is critical:
- Evidence characteristics: Relevant, reliable, sufficient, and timely
- Statistical sampling: Uses mathematical probability to select samples and quantify sampling risk
- Non-statistical (judgmental) sampling: Based on auditor judgment; does not allow mathematical measurement of sampling risk
- Attribute sampling: Tests the rate of occurrence of a characteristic (used in compliance testing)
- Variable sampling: Estimates monetary values or quantities (used in substantive testing)
Key Sampling Concepts
- Confidence level: The probability that the sample result reflects the population (typically 95%)
- Tolerable error rate: The maximum error rate the auditor will accept
- Expected error rate: The anticipated error rate in the population
- Sample size relationship: Higher confidence levels and lower tolerable error rates require larger samples
Internal Controls
IS auditors must understand the types and objectives of internal controls:
- Preventive controls: Prevent errors or irregularities from occurring (e.g., access controls, input validation)
- Detective controls: Identify errors or irregularities after they occur (e.g., audit logs, reconciliations)
- Corrective controls: Fix issues identified by detective controls (e.g., incident response, backup restoration)
- Compensating controls: Alternative controls that reduce risk when primary controls are insufficient
Computer-Assisted Audit Techniques
CAATs are essential tools for IS auditors:
- Generalized audit software (GAS): Tools like ACL and IDEA that analyze large datasets
- Test data method: Processing fictitious transactions through production systems to test controls
- Integrated test facility (ITF): Creating a fictitious entity within a production system to test processing without affecting real data
- Parallel simulation: Reprocessing actual data through auditor-controlled programs to verify results
- Embedded audit modules: Code embedded in production systems that captures transactions meeting specified criteria
Key Formulas and Relationships
- Audit risk = Inherent risk x Control risk x Detection risk
- Higher inherent risk requires more extensive testing
- Lower control risk (stronger controls) allows reduced substantive testing
- Detection risk is the only component the auditor can directly control through testing procedures
CISA Exam Tips for Domain 1
Focus on understanding the audit process flow from planning through reporting. Know the differences between types of controls, testing methods, and sampling approaches. Practice applying these concepts to scenario-based questions, as Domain 1 questions often present realistic audit situations requiring professional judgment.