CISA
What should you ask in a CISA interview, and how should candidates answer?
A CISA should be able to plan and run an audit that changes something, not just tick boxes. These questions test the five exam domains in practice, with what a strong answer covers. Candidates get the questions to prepare for and three to ask back.
What should an employer ask a CISA candidate?
Each question maps to an exam domain, so you test what the role needs. Score each answer 1 to 4 on the free scorecard below.
How do you plan a risk-based audit?
Listen for: Understand the business and its risks, then set scope, objectives, criteria, resources and the testing approach.
Domain 1: Information System Auditing Process
How do you choose a sample, and how big should it be?
Listen for: Statistical or judgmental, driven by risk and the population, with the reasoning written down.
Domain 1: Information System Auditing Process
How would you audit our IT governance?
Listen for: Strategy alignment, roles and accountability, policies, performance measures, and a framework to audit against.
Domain 2: Governance and Management of IT
What do you check on a system implementation project?
Listen for: Business case, requirements, testing, change control, go-live readiness and a post-implementation review.
Domain 3: Acquisition, Development and Implementation
How do you test our backup and recovery?
Listen for: Evidence of real restores, recovery objectives met, and disaster recovery test results, not just the policy.
Domain 4: Operations and Business Resilience
How do you audit change management?
Listen for: Sample changes for approval, testing and segregation of duties, and look hard at emergency changes.
Domain 4: Operations and Business Resilience
How do you audit user access?
Listen for: Joiners, movers and leavers, privileged accounts, and evidence that periodic reviews happened and acted.
Domain 5: Protection of Information Assets
A manager disputes your finding. What do you do?
Listen for: Go back to evidence and criteria, agree the root cause, an action and an owner, escalate if needed, and stay independent.
Domain 1: reporting
CISA interview scorecard
CISA interview scorecard
Candidate: ______ Interviewer: ______ Date: ______
| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How do you plan a risk-based audit? | Understand the business and its risks, then set scope, objectives, criteria, resources and the testing approach. | |
| 2 | How do you choose a sample, and how big should it be? | Statistical or judgmental, driven by risk and the population, with the reasoning written down. | |
| 3 | How would you audit our IT governance? | Strategy alignment, roles and accountability, policies, performance measures, and a framework to audit against. | |
| 4 | What do you check on a system implementation project? | Business case, requirements, testing, change control, go-live readiness and a post-implementation review. | |
| 5 | How do you test our backup and recovery? | Evidence of real restores, recovery objectives met, and disaster recovery test results, not just the policy. | |
| 6 | How do you audit change management? | Sample changes for approval, testing and segregation of duties, and look hard at emergency changes. | |
| 7 | How do you audit user access? | Joiners, movers and leavers, privileged accounts, and evidence that periodic reviews happened and acted. | |
| 8 | A manager disputes your finding. What do you do? | Go back to evidence and criteria, agree the root cause, an action and an owner, escalate if needed, and stay independent. |
Source: https://credentialpress.com/guides/cisa-interview-questions
Which questions should a CISA candidate prepare for?
Why CISA?
How to answer: It is the audit credential employers ask for by name. Say which audits you have run or supported.
Which domain do you know best?
How to answer: Name it, give one audit example, then the weakest and how you are closing the gap.
Tell me about a finding that changed something.
How to answer: The risk, the evidence, the action agreed, and what was different afterward.
How do you stay independent when you know the team well?
How to answer: Evidence first, the same criteria for everyone, and declaring any conflict.
What should a candidate ask the employer?
- Is the audit plan risk-based, and who approves it?
- Which frameworks and standards do you audit against?
- How are findings tracked to closure?
Where next?
Also free: the CISA mind map and the CISA 10-question quiz, plus every other credential on our study tools page. For the full syllabus, the CISA Exam Guide and the CISA Practice Questions go domain by domain.
Frequently asked questions
What should an employer ask a CISA candidate?
Questions that test each exam domain in practice, for example: How do you plan a risk-based audit? How do you choose a sample, and how big should it be? How would you audit our IT governance?
What should a CISA candidate ask the employer?
Is the audit plan risk-based, and who approves it? Which frameworks and standards do you audit against? How are findings tracked to closure?
How should a candidate prepare for a CISA interview?
It is the audit credential employers ask for by name. Say which audits you have run or supported.
Which books go deeper on CISA?

Certified Information Systems Auditor. 12 chapters, 355 pages.

Practice questions with full rationales, sized to the published domain weights. 214 pages.
Sources
- ISACA, CISA certification page, read 2 October 2026
- ISACA, exam candidate guides, read 2 October 2026
- ISACA press release, 2024: CISA exam updated
Credential Press is independent of ISACA.