CISA

What should you ask in a CISA interview, and how should candidates answer?

A CISA should be able to plan and run an audit that changes something, not just tick boxes. These questions test the five exam domains in practice, with what a strong answer covers. Candidates get the questions to prepare for and three to ask back.

What should an employer ask a CISA candidate?

Each question maps to an exam domain, so you test what the role needs. Score each answer 1 to 4 on the free scorecard below.

  1. How do you plan a risk-based audit?

    Listen for: Understand the business and its risks, then set scope, objectives, criteria, resources and the testing approach.

    Domain 1: Information System Auditing Process

  2. How do you choose a sample, and how big should it be?

    Listen for: Statistical or judgmental, driven by risk and the population, with the reasoning written down.

    Domain 1: Information System Auditing Process

  3. How would you audit our IT governance?

    Listen for: Strategy alignment, roles and accountability, policies, performance measures, and a framework to audit against.

    Domain 2: Governance and Management of IT

  4. What do you check on a system implementation project?

    Listen for: Business case, requirements, testing, change control, go-live readiness and a post-implementation review.

    Domain 3: Acquisition, Development and Implementation

  5. How do you test our backup and recovery?

    Listen for: Evidence of real restores, recovery objectives met, and disaster recovery test results, not just the policy.

    Domain 4: Operations and Business Resilience

  6. How do you audit change management?

    Listen for: Sample changes for approval, testing and segregation of duties, and look hard at emergency changes.

    Domain 4: Operations and Business Resilience

  7. How do you audit user access?

    Listen for: Joiners, movers and leavers, privileged accounts, and evidence that periodic reviews happened and acted.

    Domain 5: Protection of Information Assets

  8. A manager disputes your finding. What do you do?

    Listen for: Go back to evidence and criteria, agree the root cause, an action and an owner, escalate if needed, and stay independent.

    Domain 1: reporting

CISA interview scorecard

CISA interview scorecard

Candidate: ______ Interviewer: ______ Date: ______

#QuestionListen forScore 1 to 4
1How do you plan a risk-based audit?Understand the business and its risks, then set scope, objectives, criteria, resources and the testing approach.
2How do you choose a sample, and how big should it be?Statistical or judgmental, driven by risk and the population, with the reasoning written down.
3How would you audit our IT governance?Strategy alignment, roles and accountability, policies, performance measures, and a framework to audit against.
4What do you check on a system implementation project?Business case, requirements, testing, change control, go-live readiness and a post-implementation review.
5How do you test our backup and recovery?Evidence of real restores, recovery objectives met, and disaster recovery test results, not just the policy.
6How do you audit change management?Sample changes for approval, testing and segregation of duties, and look hard at emergency changes.
7How do you audit user access?Joiners, movers and leavers, privileged accounts, and evidence that periodic reviews happened and acted.
8A manager disputes your finding. What do you do?Go back to evidence and criteria, agree the root cause, an action and an owner, escalate if needed, and stay independent.

Source: https://credentialpress.com/guides/cisa-interview-questions

Which questions should a CISA candidate prepare for?

  1. Why CISA?

    How to answer: It is the audit credential employers ask for by name. Say which audits you have run or supported.

  2. Which domain do you know best?

    How to answer: Name it, give one audit example, then the weakest and how you are closing the gap.

  3. Tell me about a finding that changed something.

    How to answer: The risk, the evidence, the action agreed, and what was different afterward.

  4. How do you stay independent when you know the team well?

    How to answer: Evidence first, the same criteria for everyone, and declaring any conflict.

What should a candidate ask the employer?

  • Is the audit plan risk-based, and who approves it?
  • Which frameworks and standards do you audit against?
  • How are findings tracked to closure?

Where next?

Also free: the CISA mind map and the CISA 10-question quiz, plus every other credential on our study tools page. For the full syllabus, the CISA Exam Guide and the CISA Practice Questions go domain by domain.

Frequently asked questions

What should an employer ask a CISA candidate?

Questions that test each exam domain in practice, for example: How do you plan a risk-based audit? How do you choose a sample, and how big should it be? How would you audit our IT governance?

What should a CISA candidate ask the employer?

Is the audit plan risk-based, and who approves it? Which frameworks and standards do you audit against? How are findings tracked to closure?

How should a candidate prepare for a CISA interview?

It is the audit credential employers ask for by name. Say which audits you have run or supported.

Which books go deeper on CISA?

Cover of CISA Exam Guide

CISA Exam Guide

Certified Information Systems Auditor. 12 chapters, 355 pages.

Cover of CISA Practice Questions

CISA Practice Questions

Practice questions with full rationales, sized to the published domain weights. 214 pages.