Courseiva

CISA Governance and Management of IT Practice Question

A company is considering restructuring its IT department from a centralized to a decentralized model to give business units more autonomy. What is a PRIMARY governance risk associated with this move?

⚠ Common exam trap

CISA often tests whether candidates confuse operational risks (cost overruns, vendor management) with governance risks (policy and control consistency), so the trap is picking a cost-related option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inconsistent IT policies and security controls across business units.

Decentralizing IT gives business units autonomy, but the primary governance risk is that each unit may adopt its own policies, standards, and security controls. This fragmentation leads to inconsistent security postures, compliance gaps, and difficulty enforcing enterprise-wide governance. The core risk is loss of centralized control over policy and security consistency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Difficulty in managing vendor contracts due to decentralization.

    Why it's wrong here

    Vendor contracts can still be negotiated centrally or by a shared procurement function after decentralisation, so this is not the primary governance risk. It is tempting because fragmented purchasing does occur in practice, but the core exposure is inconsistent policy, security and compliance enforcement across autonomous units.

  • ✗

    Reduced innovation due to lack of central coordination.

    Why it's wrong here

    Decentralisation typically increases local experimentation, so reduced innovation from absent central coordination inverts the actual risk. It is tempting because central coordination genuinely drives standards and shared platforms, but the governance exposure here is duplicated spend and inconsistent control across business units.

  • ✗

    Increased risk of project cost overruns.

    Why it's wrong here

    Cost overruns stem from weak project controls, not governance structure; decentralisation's primary governance risk is fragmented decision rights and inconsistent standards across units. Centralised models concentrate cost oversight, so this option describes a symptom of poor budgeting. It would fit a question about project management maturity rather than governance design.

  • ✓

    Inconsistent IT policies and security controls across business units.

    Why this is correct

    Decentralisation pushes policy and control decisions to individual business units, which then apply differing standards. The stem's autonomy constraint means no single authority enforces uniform configuration, so inconsistent IT policies and security controls across business units become the primary governance risk.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.