CISA Domain 1, the Information Systems Auditing Process, carries 18% of the exam. On a 150-question form that is roughly 27 questions. It splits cleanly into two halves: planning an audit engagement, and executing one. Planning covers the professional standards and ethics you work under, the different kinds of engagements that exist, risk-based selection of what to audit, and the taxonomy of controls you will evaluate. Execution covers running the engagement as a project, testing and sampling, collecting evidence, using data analytics, reporting, and the quality assurance applied to the audit function itself.
Two ideas run through all of it: independence and evidence. The auditor forms an opinion supported by sufficient and appropriate evidence, and the auditor never owns or operates the control being examined. Hold those two sentences in mind while you read a Domain 1 question and you will pick the credited answer more often than not. Almost every trap in this domain is a tempting option that violates one of them.
What does CISA Domain 1 actually cover?
The planning half starts with the ISACA IT Audit Framework, usually written as ITAF. It has three tiers and the exam expects you to know which is which. Standards are mandatory, and where a standard says "shall," it is not a matter of judgment. Guidelines are strongly recommended and explain how to apply the standards in practice; if you take a different route, you have to show your route still meets the intent. Tools and techniques are optional aids: templates, checklists, methods. When a question asks which tier must be followed, the answer is the standards, and failing to conform to one is something you disclose rather than quietly absorb.
Then come the engagement types. An audit is a formal, evidence-based engagement producing an independent opinion, and it carries the highest level of assurance. An assessment evaluates something against criteria but with less independence, less evidence, and no formal opinion. A review is lighter still: inquiry and analytical procedures, findings described without audit-level assurance. Under that sit the flavors named in stems: compliance, financial, operational, integrated, forensic, administrative. You also need SOC reports. SOC 1 covers controls relevant to a user entity's financial reporting; SOC 2 covers security, availability, processing integrity, confidentiality, and privacy. Type 1 describes design at a point in time; Type 2 covers operating effectiveness over a period, so Type 2 gives you more.
If you are still getting oriented across the five domains, CISA domains explained puts this one in context, and what the CISA exam is covers the format and requirements first.
How does risk-based audit planning work?
Audit resources are finite, so you cannot look at everything every year. Risk-based planning starts with the audit universe, which is the complete population of auditable entities: every system, process, business unit, and third-party relationship inside the audit function's scope. The audit universe is not the plan. It is the input to the plan. The annual plan is selected out of it, weighted toward risk, and approved by the audit committee or equivalent.
The piece the exam leans on hardest is the audit risk model. Audit risk is inherent risk times control risk times detection risk. Inherent risk is what exists before any control is applied. Control risk is the chance the controls in place fail to prevent or detect a problem. Detection risk is the chance your own procedures miss something that is really there, and it is the only one of the three you control directly.
Work an example. You are planning an audit of a payment system that processes high volumes of sensitive financial data, so inherent risk is high. Last year's findings show change management on that platform is weak, so control risk is high too. What has to happen to detection risk? It has to come down, which means more extensive procedures: larger samples, reperformance instead of inquiry, maybe full-population analytics. If you cannot drive it that low with the resources you have, you narrow the scope or ask for more people. What you do not do is run the thin program you would run on a low-risk system and call the result assurance.
Materiality sits alongside this. It is the threshold at which a finding is significant enough to affect the opinion or the decisions of the report's users. You set it in planning, adjust it as evidence arrives, and apply it in reporting. Findings below the threshold can still go to management as observations without driving the opinion.
How do you classify controls on the CISA exam?
Three overlapping schemes, and the exam mixes them freely.
By timing: preventive controls stop the event happening, detective controls identify that it happened, corrective controls restore the correct state afterward. Input validation that rejects malformed data is preventive. A log review that surfaces anomalies is detective. Restoring from backup is corrective.
By domain: managerial controls are policies, procedures, training, and governance. Technical controls are implemented in technology, such as firewalls, encryption, and access control lists. Physical controls are badge readers, cages, CCTV, and fire suppression.
By scope: general controls, often called ITGCs, apply across the environment and support every application in it. Application controls are specific to one application and govern input, processing, and output for its data. The dependency runs one way only, and the exam tests the direction: weak general controls undermine reliance on application controls, never the reverse. Domain 3 gives that pair its fullest workout.
Add compensating controls. When the primary control is genuinely infeasible, for example separation of duties in a team of three, a compensating control such as enhanced management review with a full audit trail can offset the risk. Your job is to evaluate whether it actually reduces the risk to an acceptable level, not whether it exists on paper.
What does the execution half of Domain 1 test?
Run the engagement like a project. An engagement plan documents objectives, scope, criteria, approach, staffing, and schedule, and the audit manager approves it before fieldwork. The audit program is the detailed testing plan underneath it, mapping each procedure back to an objective. Supervision is mandatory. A finding the working papers do not support gets challenged in review and should never reach the report.
Sampling is where the technical questions live. Tests of controls ask whether a control operated as designed. Substantive tests examine the data itself. Strong controls let you reduce substantive testing; weak controls force you to increase it. Statistical sampling gives every item a known, non-zero chance of selection and lets you project results mathematically to the population. Non-statistical sampling, whether haphazard or judgmental, does not support that projection, though it is entirely appropriate when you are hunting a specific irregularity in a known high-risk subset. Then match the method to the test: attribute sampling for tests of controls, because the attribute is a yes or no characteristic such as "approved before posting," and variable sampling for substantive tests, because you are estimating a quantity.
Evidence has two properties worth memorizing. Sufficient means enough of it. Appropriate means relevant to the objective and reliable in source. Reliability rises when evidence comes from outside the organization, when you obtain it directly yourself, when it is documentary, and when it is an original rather than a copy. That ranks the techniques for you. Inquiry is the weakest, because you are relying on what someone told you; it points you at what to test rather than proving anything. Observation beats it, though people behave differently when watched. Inspection and confirmation are stronger. Reperformance, where you re-execute the control yourself and compare results, is the strongest of the set.
Analytics extends the same logic. Computer-assisted audit techniques, generalized audit software, test data, and audit algorithms let you test whole populations instead of samples, which removes sampling risk entirely. One caution the exam likes: validate the extraction first, reconciling record counts and totals back to the source system. An analytics result from incomplete data is not evidence.
Reporting has a fixed anatomy. Criteria is what should be, condition is what you found, cause is why the gap exists, and effect is what it means. Recommendations must address the cause. Management responds and owns the remediation dates; you follow up later to confirm the actions happened. The audit function itself also needs a quality assurance and improvement program, with ongoing internal review and an external quality assessment at least every five years.
What are the most common CISA Domain 1 traps?
Three come up repeatedly.
The first is the auditor who fixes the problem. You find a control weakness, and one option has you correcting it, configuring the setting, or writing the missing procedure. That option is almost always wrong. You report the finding to the people who own the control. The moment you remediate it, you cannot objectively audit it. The same logic covers the auditor who advised management on designing a control and is later assigned to audit that control: disclose the impairment and get recused, even when nobody else is available. "No one else can do it" is the bait in that stem, not a reason.
The second is control classification under pressure. Candidates who know the definitions still misclassify in scenarios because they classify by what the control feels like rather than by when it acts. A firewall rule blocking traffic is preventive. A firewall log reviewed weekly is detective. Same device, different control, different answer. Ask when it acts relative to the event, every time.
The third is sampling method choice. Reaching for statistical sampling because it sounds more rigorous is a mistake when the objective does not need projection, and reaching for judgmental sampling when the question explicitly wants a conclusion about the whole population is worse. Read the objective in the stem, then pick the method that supports exactly the conclusion being asked for. Attribute for controls, variable for quantities, statistical when you must project.
All three sit underneath the qualifier wording the exam uses throughout, which we take apart in MOST, BEST, and FIRST questions.
Where does study time in Domain 1 pay off?
Here is an opinion. Do not spend your Domain 1 hours memorizing the audit types and the SOC matrix. Those are worth maybe a handful of questions and you can learn them in an afternoon. Spend the hours on the control taxonomy and the independence reflex, because both of those pay off outside Domain 1.
Control classification shows up everywhere. When Domain 4 asks about backup and recovery, or Domain 5 asks about encryption and access management, the question is often still "what type of control is this and what is the gap." Those two domains are 52% of the exam. Getting fluent with preventive, detective, corrective, managerial, technical, physical, and general versus application in Domain 1 quietly raises your score across half the paper. The independence reflex does the same thing for every scenario question that offers you a helpful-sounding action.
Study the audit risk model and the evidence reliability ranking second: compact, tested precisely, easy points. Leave the quality assurance section and the project management milestones for last. Real content, thinly represented.
Our CISA study guide teaches Domain 1 in exactly this order, from the auditor's decision seat rather than the practitioner's, and the practice exams are blueprint-weighted so you get Domain 1 questions in proportion to the real thing.
Domain 1 is not the biggest domain, but it is the one that teaches you how to read every other domain's questions. Study it first, and study it for the reflexes rather than the vocabulary. When you are ready to move on, Domain 2 on governance and management of IT carries the same 18% weight and picks up where the audit charter leaves off.
FAQ
How many questions is CISA Domain 1 on the exam?
Domain 1 is 18% of the exam. With 150 multiple-choice questions on a form, that works out to roughly 27 questions. ISACA does not publish an exact per-domain item count, and forms vary, so treat 27 as a planning figure rather than a fixed number.
Is Domain 1 the easiest CISA domain?
It is often the most familiar for practicing auditors, since it describes the work they already do. That familiarity is a trap of its own, because the exam tests the textbook version of the process rather than your firm's version. If your organization takes shortcuts on independence or evidence, unlearn them before exam day.
What is the difference between a test of controls and a substantive test?
A test of controls checks whether a control operated as designed during the audit period, for example verifying that a sample of transactions was approved before posting. A substantive test examines the data itself, for example reconciling a balance to an independent source. Strong controls let you reduce substantive testing; weak controls mean you have to increase it.
Why is inquiry considered weak audit evidence?
Because you are relying on what someone told you rather than on something you verified. Inquiry is useful for identifying where to look, but on its own it does not support a conclusion. Reperformance, where you re-execute the control and compare the result yourself, sits at the opposite end of the reliability scale.
Should I study Domain 1 before the other CISA domains?
Yes, in our view. Domain 1 establishes the independence and evidence lens that the other four domains are tested through, and the control taxonomy you learn here is reused constantly in Domains 4 and 5. Learning it first makes the technical domains easier to read.
Looking for a plain-English CISA guide? ISACA CISA: Certified Information Systems Auditor Study Guide covers all five domains with four full-length practice exams, every answer explained.
Simply Certified is an independent publisher. CISA and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.