CPA Exam · 10 min read

Complete CPA Information Systems and Controls Study Guide 2026

Rob Pfleghardt

10-year PwC alumnus · Founder of VoraPrep · Previously CPA-licensed

Complete CPA Information Systems and Controls Study Guide 2026

Key Takeaways

  • - Passing Score: 75 (on a 0-99 scaled score)
  • The Information Systems and Controls (ISC) exam tests your ability to apply an accountant's judgment to technology.
  • The ISC exam is a 4-hour test designed to assess both your foundational knowledge and your ability to apply it in complex, real-world scenarios.
  • To study smart for 2026, you must master the AICPA Blueprint.
  • The most challenging ISC questions are scenarios where you must evaluate a situation and recommend an action.

You feel confident about IT controls, then bam—an exam question hits you with a complex SOC 2 report scenario. The #1 reason candidates stumble here isn’t forgetting the five Trust Services Criteria; it’s failing to connect a specific control deficiency to a tangible business risk. The ISC exam is a test of judgment, and the secret is learning to think through problems like an IT auditor, not just memorizing a glossary of terms.

Quick answer

The CPA Information Systems and Controls (ISC) exam is a 4-hour discipline section testing IT governance, data analytics, and cybersecurity. To pass, you need a scaled score of 75. The exam format is 50% MCQs (50 questions in 2 testlets) and 50% TBSs (7 simulations in 3 testlets), focusing on judgment over memorization.

The CPA exam has a <50% pass rate.

VoraPrep's AI finds your weak spots before the exam does — adaptive practice that actually moves your score.

Try Free →

Key facts

  • Passing Score: 75 (on a 0-99 scaled score)
  • Exam Discipline: One of three choices (BAR, ISC, TCP) alongside the three core sections (FAR, AUD, REG)
  • Exam Format: 4 hours, 50% Multiple-Choice Questions (MCQs) and 50% Task-Based Simulations (TBSs)
  • Question Count: 50 MCQs and 7 TBSs
  • Testing Window: Continuous testing available year-round for 2026
  • Official Body: AICPA (American Institute of Certified Public Accountants)

What Does the CPA ISC Exam Actually Test?

The Information Systems and Controls (ISC) exam tests your ability to apply an accountant's judgment to technology. It's not about being an IT expert. It’s about understanding how information systems, data, and security controls impact a business's operations and financial reporting integrity.

Think of it this way: An auditor needs to know if a company's ERP system can be trusted. A consultant needs to advise on the risks of moving to a cloud provider. A CFO needs to understand the data behind a major business decision. ISC tests the skills required for all these roles. You'll be evaluated on your ability to identify technology-related risks, evaluate the design of controls meant to mitigate those risks, and understand how data analytics can uncover insights and anomalies.

What is the ISC Exam Format and Structure?

The ISC exam is a 4-hour test designed to assess both your foundational knowledge and your ability to apply it in complex, real-world scenarios. The score is split evenly between two question types:

  • Multiple-Choice Questions (MCQs): Accounting for 50% of your score, you'll face 50 MCQs distributed across two testlets. These questions test your grasp of definitions, frameworks, and the direct application of control concepts. They often contain subtle distractors designed to trap candidates who rely on surface-level knowledge.
  • Task-Based Simulations (TBSs): The other 50% of your score comes from 7 TBSs spread across three testlets. These are mini case studies. You might be asked to analyze a system-generated report for control deficiencies, review a company's disaster recovery plan, or interpret the results of a data analytics procedure. This is where your critical thinking is truly measured.

Passing requires a scaled score of 75. This is not a raw percentage. The AICPA uses a scaling formula that accounts for the difficulty of the questions you receive. Your focus should be on deep understanding, not just hitting a target number of correct answers. For effective time management, aim for about 1.5-2 minutes per MCQ and 15-25 minutes per TBS.

Key Topics on the ISC Exam: The AICPA Blueprint Decoded

To study smart for 2026, you must master the AICPA Blueprint. The ISC content is divided into three domains, each with a specific weight.

Area 1: Information Systems and Risk Management (35-45%)

This is the largest and most foundational area. It covers IT governance, risk assessment, and the internal controls that form the bedrock of a reliable IT environment.

  • High-weight topics: COSO Internal Control – Integrated Framework as it applies to IT, IT general controls (ITGCs) vs. application controls, business continuity planning, and disaster recovery.
  • Key Skill: Understanding SOC 1 vs. SOC 2 Reports: This is a frequently tested distinction. A SOC 1 report focuses on internal controls over financial reporting (ICFR) and is primarily for the user entity's auditors. A SOC 2 report focuses on controls related to security, availability, processing integrity, confidentiality, and privacy (the Trust Services Criteria) and is for a broader range of stakeholders concerned with data security. You must know which report to use for which scenario.

Area 2: Data Management and Analytics (25-35%)

This domain tests your understanding of how data is structured, governed, and used to make business decisions.

  • High-weight topics: Database concepts, data warehousing, data visualization, and applying data analytics procedures.
  • Key Skill: The Components of Data Governance: Don't just memorize the term. Understand its parts: data quality (ensuring accuracy and completeness), data stewardship (assigning responsibility for data assets), and data architecture (the blueprint for how data is collected, stored, and used).

Area 3: Security and Confidentiality (25-35%)

This area covers the principles and controls needed to protect an organization's information assets from threats.

  • High-weight topics: Network security controls (firewalls, intrusion detection systems), encryption, identity and access management (IAM), and incident response.
  • Key Skill: Cloud Computing and the Shared Responsibility Model: The exam assumes a modern, cloud-based environment. You must understand the shared responsibility model, where the cloud provider (like AWS or Azure) is responsible for the security of the cloud, while the customer is responsible for security in the cloud (e.g., configuring access controls, managing user data).

The ISC High-Scorer's Playbook: A Decision-Tree for Controls

The most challenging ISC questions are scenarios where you must evaluate a situation and recommend an action. Memorization fails here. You need a mental model. Here’s the decision-tree approach we teach at VoraPrep.

Scenario: VoraCorp, a manufacturing company, has implemented a new ERP system. The IT department has set up user accounts. An internal auditor, Ms. Chen, discovers several employees in accounts payable can both create new vendors in the master file and approve payments. The Tempting Wrong Answer: "Implement strong passwords and multi-factor authentication (MFA)." This is a common trap. MFA prevents unauthorized users from getting in. The problem here is that authorized users have conflicting permissions. It's a segregation of duties (SoD) failure. The High-Scorer's Decision Tree:
  1. Frame the Risk Using a Known Framework (COSO):
  • Condition: Users can create vendors and approve payments.
  • Framework Link: This directly violates COSO Principle 10 (Selects and Develops Control Activities) and Principle 11 (Selects and Develops General Controls over Technology). Specifically, it's a failure in segregation of duties.
  • Action: State the specific risk: An employee could create a fake vendor, approve a fake invoice, and pay themselves, leading to asset misappropriation.
  1. Identify the Control Objective:
  • Condition: A critical SoD weakness exists.
  • Objective: The primary goal isn't just "better security." It's to ensure that no single individual can initiate, authorize, record, and have custody of an asset or transaction.
  • Action: Define the required control: The ability to manage the vendor master file must be separate from the ability to process and approve payments.
  1. Propose a Solution (Prioritize System Controls over Manual Ones):
  • Condition: The ERP system's user permissions are configured improperly.
  • Primary Solution (System-based): Implement Role-Based Access Control (RBAC). Create a "Vendor Management" role and a separate "Payment Approver" role. Ensure no user is assigned both roles. This is the most effective and efficient control.
  • Secondary Solution (Manual Compensating Control): If RBAC can't be implemented immediately, propose a mandatory, independent review of all new vendors by a manager in the procurement department before any payments can be made. This is less efficient but can temporarily mitigate the risk.

This structured thinking—linking the weakness to a framework, defining the objective, and prioritizing a system-based solution—is exactly how you dismantle complex TBSs and demonstrate the judgment the exam demands. Try applying this logic to VoraPrep's free practice questions to see the difference it makes.

How Should I Study for the ISC Exam in 2026?

A passing ISC score is built on a smart study strategy, not just brute force.

  1. Prioritize Based on the Blueprint: The blueprint is your map. Information Systems and Risk Management (35-45%) is your starting point. Master ITGCs and the COSO framework's application to IT before diving deep into data analytics or cybersecurity specifics.
  2. Think in Risks and Controls, Not Just Terms: For every concept (e.g., "encryption"), ask these three questions:
  • What risk does this mitigate? (Unauthorized access to data in transit or at rest).
  • Where would this be applied? (VPNs, databases, file transfers).
  • What are its limitations? (Doesn't prevent an authorized user from misusing data).
  1. Embrace Active Recall with Practice Questions: Passive reading is not enough. You need to constantly test yourself. With VoraPrep's 9,500+ practice questions, you can drill down on specific blueprint areas. After every question, read the full explanation—even if you got it right. Understand why the wrong answers are wrong. That's where true learning happens.
  2. Use Adaptive Technology to Fix Weaknesses: You don't have time to waste studying what you already know. VoraPrep's adaptive learning engine identifies your weak spots from your practice question performance and automatically serves you more questions on those topics, ensuring your study time is always focused on closing your knowledge gaps.
  3. Don't Isolate ISC from Other Sections: ISC concepts have huge overlaps with AUD. Understanding ITGCs and SOC reports from an ISC perspective will dramatically improve your ability when evaluating internal control design in AUD. Seeing these connections makes your knowledge more durable.

Which ISC Study Resources Are Best?

Your choice of study material can be the difference between passing and retaking. Here’s a breakdown of your options.

FeatureVoraPrepGeneric TextbooksFree Online Resources
Practice Questions9,500+ MCQs & TBSs with detailed "why" explanationsLimited, often with brief or no explanationsUnreliable quality, often outdated
Adaptive LearningYes, our engine targets your weak areas to optimize study timeNoNo
Expert SupportVory, our 24/7 AI tutor, provides instant answers and examplesNoCommunity forums, answers may be incorrect
Application FocusTeaches judgment and decision-making for complex scenariosFocuses on definitions and rote memorizationSurface-level explanations, lacks depth for TBSs
Cost-Effectiveness$29/month or $249/year with a 14-day free trialHigh one-time cost ($1,500+)Free, but high cost in wasted time and potential failure

For a full breakdown of how VoraPrep stacks up, see our side-by-side course comparison. An investment in a quality review course is an investment in your career and future salary as a CPA, which typically ranges from $75,000 to $150,000.

--- Ready to Pass Your CPA Exam? Don't just memorize ISC concepts; master them. VoraPrep's adaptive learning engine, massive question bank, and 24/7 Vory tutor are designed to teach you the judgment you need to pass. Start building your confidence today. Visit voraprep.com to get started. Start Your Free 7-Day Trial at voraprep.com →

Frequently asked questions

What topics are on the CPA ISC exam?

The ISC exam covers three domains: Information Systems and Risk Management (IT governance, COSO, SOC reports), Data Management and Analytics (databases, data governance, analytics tools), and Security and Confidentiality (cybersecurity, cloud controls, incident response).

How many hours should I study for ISC?

Plan for 80-100 hours of focused study for the ISC section. This time should be allocated to understanding concepts, drilling practice questions and simulations, and reviewing your weak areas.

Is the ISC section difficult?

Difficulty is subjective, but ISC is considered challenging due to its blend of technical concepts and application-based questions. Candidates without an IT audit background may face a steeper learning curve, but it is passable with a focus on risk and control principles.

Can I pass ISC without an IT background?

Yes. The exam tests your ability to apply an accountant's judgment to IT risks, not your ability to be a system administrator. Focus on the "why" behind controls and their business impact, which is a core CPA skill.

How do I prepare for ISC Task-Based Simulations (TBSs)?

The best way is through relentless practice. Use a decision-tree approach: identify the risk, define the control objective, and propose a solution. Always read the prompt carefully to understand exactly what is being asked.

Official resources and references

Studying for the CPA?

Stop guessing which topics to review. VoraPrep's adaptive engine diagnoses exactly where you're losing points and rebuilds those areas. 10 minutes a day, measurable score improvement.

Start your free trial → voraprep.com
RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding an active CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →

Don't let this be why you retake the CPA.

Most candidates fail because they study the wrong things, not because they don't study enough. VoraPrep's AI identifies your actual weak spots and targets them — so you walk in knowing exactly where you're strong.

Start Free — No Credit Card →

Keep reading