Domain 1 is the auditor's own craft: how an IS audit is planned, executed, and reported. Under the CISA content outline effective August 2024, it carries 18% of the exam, and this chapter covers its planning half — the part of every engagement that succeeds or fails before fieldwork begins. The four sections below follow the order in which a real engagement unfolds: the standards and ethics that authorize and constrain the auditor, the kinds of engagements an IS auditor performs, the risk-based plan that aims effort where it matters most, and the control types that the plan is built to test. Chapter 2 continues with execution: managing the audit project, testing and sampling, collecting evidence, applying data analytics, reporting results, and quality assurance. The domain's logic is sequential, and the exam rewards candidates who think in that order — nothing in Chapter 2 works unless the planning in this chapter was done properly, and candidates who master planning answer execution questions better too, because every testing decision traces back to a planning decision made here.
1A1 IS Audit Standards, Guidelines, and Codes of Ethics
Every CISA begins here, because the credential itself rests on this material: adhering to ISACA's Code of Professional Ethics is one of the steps to certification, and the Code is the only part of the CISA body of knowledge for which ISACA publishes the controlling text free of charge. The Code opens by stating its purpose — to guide the professional and personal conduct of members and certification holders — and then sets out seven tenets, in ISACA's words:
- Support the implementation of, and encourage compliance with, appropriate standards and procedures for the effective governance and management of enterprise information systems and technology, including audit, control, security and risk management.
- Perform their duties with objectivity, due diligence and professional care, in accordance with professional standards.
- Serve in the interest of stakeholders in a lawful manner, while maintaining high standards of conduct and character, and not discrediting their profession or the Association.
- Maintain the privacy and confidentiality of information obtained in the course of their activities unless disclosure is required by legal authority. Such information shall not be used for personal benefit or released to inappropriate parties.
- Maintain competency in their respective fields and agree to undertake only those activities they can reasonably expect to complete with the necessary skills, knowledge and competence.
- Inform appropriate parties of the results of work performed, including the disclosure of all significant facts known to them that, if not disclosed, may distort the reporting of the results.
- Support the professional education of stakeholders in enhancing their understanding of the governance and management of enterprise information systems and technology, including audit, control, security and risk management.
Three of these tenets do the heaviest work on the exam. Objectivity and professional care (tenet 2) are operationalized through two supporting concepts. Independence, in ISACA's glossary, is freedom from conflict of interest and undue influence — the auditor must be free to make decisions uninfluenced by the managers and employees being audited. Due professional care is the diligence that a person with special skill would exercise under the circumstances: the standard is not perfection, but the care a competent professional would take. Confidentiality (tenet 4) is near-absolute — client information is never used for personal benefit and never released to inappropriate parties, no matter how informally the request arrives; only disclosure required by legal authority overrides it. Competency (tenet 5) is a continuing obligation rather than a one-time credential, which is why retaining certification requires 20 hours of continuing professional education each year and 120 hours over each three-year reporting period. It is also a per-engagement test: the auditor who lacks the skills for an assignment must say so and obtain qualified help rather than improvise on a live client system.
Beyond the Code, ISACA publishes IS audit standards and guidelines that define how engagements are conducted. The CISA task statements expect the auditor to conduct audits in accordance with IS audit standards and a risk-based IS audit strategy — standards supply the "how an audit is done," and the risk-based strategy, covered in 1A3, supplies the "where the effort goes." An auditor who performs thorough procedures but cannot show the engagement followed professional standards has missed what the exam tests: the process must be defensible, not merely diligent. And the Code's tenets are enforceable rules, not aspirations — failure to comply can lead to investigation of the member's or certification holder's conduct and, ultimately, disciplinary measures.
1A2 Types of Audits, Assessments, and Reviews
Not every assurance engagement is an audit, and the exam expects precision about the differences. An audit provides the highest level of assurance: systematic and evidence-based, performed against stated criteria, and ending in an opinion or conclusion. An assessment is broader and typically lighter — an evaluation of controls or posture against a framework, producing findings and recommendations without a formal opinion. A review is narrower still, applying limited procedures to provide limited assurance. The engagement letter, the formal document defining the IS auditor's responsibility, authority and accountability for the assignment, should make clear which of these the client is getting, because the procedures performed, the evidence bar, and the reporting all differ.
Within audits, several types recur across the exam. Internal audits are performed by or on behalf of the enterprise itself, serving management and those charged with governance. External audits are performed by independent third parties, often driven by regulatory or contractual requirements. Compliance audits test conformity with laws, regulations, policies or contracts. Operational audits examine efficiency and effectiveness — whether resources are well used, not merely whether rules were followed. Financial audits focus on the reliability of financial reporting, where the IS auditor's interest lies in the IT controls those numbers depend on. Integrated audits combine these lenses, for instance testing financial-reporting controls and operational efficiency within a single engagement.
For the IS auditor specifically, two scopes matter most. General-controls audits examine the IT environment as a whole — access management, change control, operations — the foundation on which every application depends. Application-controls audits go deeper into a single system, testing the input, processing and output controls of, say, a payroll or claims application. A recurring exam trap is the relationship between the two: weak general controls undermine reliance on application controls, because an application cannot be more trustworthy than the environment running it. Planning therefore sequences general-controls work before deep application testing whenever the auditor intends to rely on those application controls.
1A3 Risk-Based Audit Planning
The first CISA task statement defines the mission: plan an audit to determine whether information systems are protected, controlled, and provide value to the organization. "Risk-based" is the method. No budget or calendar permits testing everything, so planning allocates effort in proportion to risk, and the audit plan documents the result. ISACA's glossary defines the audit plan as containing the nature, timing and extent of audit procedures to be performed in order to obtain sufficient appropriate evidence for an opinion, and its scope notes spell out what the plan carries: the areas to be audited, the type of work planned, the high-level objectives and scope of the work — plus budget, resource allocation, schedule dates, the type of report and its intended audience.
Planning proceeds in a fixed logical order, and the exam tests the order. First, the auditor builds or refreshes the audit universe: the inventory of auditable entities — systems, processes, locations, projects. Second, a risk assessment ranks that universe by asking where things could go wrong, how badly, and how likely it is. This is where risk vocabulary must be exact. A threat is any circumstance or event with the potential to adversely impact organizational operations and assets — through unauthorized access, destruction, disclosure or modification of information, or denial of service. A threat source is what causes threat events, characterized by the intent and method aimed at exploiting a vulnerability, or by a situation and method that may exploit one accidentally. Likelihood and impact are then judged for each threat, producing the risk ranking that drives the plan.
Third, the auditor sets materiality: an item's importance judged by its impact or effect on the functioning of the entity being audited, its significance in the context of the enterprise as a whole. Materiality keeps a risk-based plan honest — a high-likelihood finding in a trivial process must not outrank a moderate risk in a system the business cannot live without. Fourth, the plan assigns procedures, people and time, explicitly considering audit risk: the risk of reaching an incorrect conclusion based on audit findings. Its three components discipline the planning. Inherent risk is the susceptibility of the area to error or fraud before any controls are considered. Control risk is the chance that the client's controls fail to prevent or detect it. Detection risk is the chance that the auditor's own procedures miss what remains. Where inherent and control risk are high, the plan must drive detection risk down through more extensive, better-designed, or more experienced testing.
Two cross-cutting points complete the picture. Project management is not a separate discipline the auditor borrows for the occasion; it is embedded in the plan itself. The budget, resource allocation and schedule dates the glossary's scope notes require are project management applied to the audit process, and the CISA tasks expect the auditor to apply project management methodologies to keep the engagement on scope, on time and on budget. And the planning sequence has a non-negotiable first step the exam returns to again and again: before designing procedures, the auditor gathers information to understand the process, its risks and its controls. Procedures designed around an unexamined process test the auditor's assumptions, not the client's reality.
1A4 Types of Controls and Considerations
The plan from 1A3 exists to test controls, so the auditor must classify them correctly. ISACA's glossary gives three functional types. Preventive controls are used to avoid undesirable events, errors and other occurrences the enterprise has determined could have a negative material effect — the locked server room, the input validation that rejects malformed data, the segregation of duties that makes fraud require collusion. Detective controls are designed to detect and report when errors, omissions and unauthorized uses or entries occur — the log review, the bank reconciliation, the exception report. Corrective controls are designed to correct errors, omissions, unauthorized uses and intrusions once they are detected — the rollback procedure, the reissued transaction, the incident response playbook. The exam's favorite trap is the control that both notices and stops: classify by primary purpose. A control that blocks an attack in real time is preventive even though it also noticed the attack; a control that merely reports it is detective.
Control considerations shape which controls the auditor expects to find and how much reliance each earns. Cost matters: a control should not cost more than the risk it mitigates, and the auditor evaluates whether the control set is proportionate, not merely present. Compensating controls matter more: where a preferred control is impractical, an alternative achieving the same objective can earn reliance — the auditor tests the compensation, not the absence. And the control environment matters most: the identical technical control earns different reliance in a disciplined environment than in a chaotic one.
Finally, the auditor must evaluate the role and impact of automatization and decision-making systems — the CISA tasks name this explicitly, and it now pervades every control type. Automated controls execute consistently but fail consistently: a misconfigured automated preventive control denies every legitimate transaction, or permits every fraudulent one, at machine speed. Decision-making systems, from rules engines to machine-learning models, introduce risks the plan must capture: biased or stale training data, logic the business cannot explain, and over-reliance by staff who stop exercising judgment. The auditor's job is not to bless automation but to evaluate it — testing whether automated controls are designed correctly, operate consistently, and remain subject to human oversight where the decision affects the enterprise's risk posture. An audit plan that treats "the system handles it" as an answer has confused a control with an excuse.