What should the IS auditor do in the given case?
Senior management has requested that an IS auditor assist the departmental management in the implementation of necessary controls.
A. Refuse the assignment since it is not the role of the IS auditor. B. Inform management of his/her inability to conduct future audits. C. Perform the assignment and future audits with due professional care. D. Obtain the approval of user management to perform the implementation and follow-up.
B. inform management of his/her inability to conduct future audits.
In this situation the IS auditor should inform management of the impairment of independence in conducting further audits in the auditee area. An IS auditor can perform nonaudit assignments where the IS auditors expertise can be of use to management; however, by performing the nonaudit assignment, the IS auditor cannot conduct the future audits of the auditee as his/her independence may be compromised. However, the independence of the IS auditor will not be impaired when suggesting/recommending controls to the auditee after he audit.