StudyToCert

All certifications / CISA / Lessons

ISACA Certified Information Systems Auditor (CISA) 2024 job practice · Domain 3: Information systems acquisition, development and implementation

Control identification and design: input, processing and output application controls

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Controls are cheapest and most effective when designed into a system rather than added after go-live. During requirements and design, the project team, with advice from security, risk and audit, should identify the risks in the business process and build in application controls to address them. The auditor can review and advise on what controls are needed, but should not design them, to protect independence when the system is audited later. Application controls aim to ensure that data is complete, accurate, valid, authorized and that processing is timely and traceable.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISA for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISA study plan