# CISA interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How do you plan a risk-based audit? | Understand the business and its risks, then set scope, objectives, criteria, resources and the testing approach. | |
| 2 | How do you choose a sample, and how big should it be? | Statistical or judgmental, driven by risk and the population, with the reasoning written down. | |
| 3 | How would you audit our IT governance? | Strategy alignment, roles and accountability, policies, performance measures, and a framework to audit against. | |
| 4 | What do you check on a system implementation project? | Business case, requirements, testing, change control, go-live readiness and a post-implementation review. | |
| 5 | How do you test our backup and recovery? | Evidence of real restores, recovery objectives met, and disaster recovery test results, not just the policy. | |
| 6 | How do you audit change management? | Sample changes for approval, testing and segregation of duties, and look hard at emergency changes. | |
| 7 | How do you audit user access? | Joiners, movers and leavers, privileged accounts, and evidence that periodic reviews happened and acted. | |
| 8 | A manager disputes your finding. What do you do? | Go back to evidence and criteria, agree the root cause, an action and an owner, escalate if needed, and stay independent. | |

Source: https://credentialpress.com/guides/cisa-interview-questions
