CISA Governance and Management of IT Practice Question
A company plans to outsource its data center operations to a cloud service provider. What is the MOST important governance consideration for the board before finalizing the contract?
⚠ Common exam trap
CISA often tests the distinction between governance and management. Candidates may choose an operational or tactical answer (like exit strategy or cost) instead of the governance-level answer that focuses on compliance and audit rights.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the contract includes clauses for regulatory compliance and audit rights.
The board's primary governance responsibility is to ensure the organization remains compliant with all applicable laws and regulations, even when operations are outsourced. Without explicit contractual clauses for regulatory compliance and audit rights, the company loses visibility and control over how its data is handled, creating legal and reputational risk. This is the most critical governance consideration because it directly addresses accountability and oversight.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Select a provider with the lowest cost per transaction.
Why it's wrong here
Lowest cost per transaction addresses procurement economics, not board-level governance of outsourced data centre risk. It is tempting because cost reduction often motivates outsourcing, but the board must first ensure accountability, oversight and risk treatment are contractually established before price is considered.
- ✗
Negotiate the transfer of existing IT staff to the provider.
Why it's wrong here
Transferring existing IT staff to the provider is a workforce transition detail, not the board's foremost governance consideration. It is tempting because TUPE-style arrangements affect cost and continuity, but the board's priority is retaining oversight and accountability for outsourced data centre risk before signing.
- ✓
Ensure the contract includes clauses for regulatory compliance and audit rights.
Why this is correct
Outsourcing data centre operations transfers processing to a third party, so the board must secure contractual regulatory compliance and audit rights. These clauses preserve oversight and evidence-gathering ability, satisfying the governance obligation for accountability over outsourced services.
- ✗
Define a detailed exit strategy for transitioning to another provider.
Why it's wrong here
An exit strategy matters for avoiding lock-in, but it addresses eventual termination rather than the board's primary governance duty when outsourcing data centre operations. It is tempting because reversibility reduces long-term risk, yet the stem asks for the most important consideration before finalising the contract.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company outsources its data center operations to a third-party provider. Which of the following is the MOST important control to include in the outsourcing contract?
medium- A.Detailed escalation procedures for incidents
- B.Service level agreements with financial penalties
- C.Requirements for encryption of data at rest
- ✓ D.Right to audit the provider's facilities and processes
Why D: The right to audit the provider's facilities and processes is the most important control because it ensures the outsourcing company can verify that the provider is complying with security, regulatory, and contractual requirements. Without audit rights, the company has no independent means to confirm that controls are effective, leaving it exposed to undetected risks.
Variation 2. An organization is planning to outsource its data center operations. Which of the following governance practices should be implemented to ensure proper oversight?
medium- A.Conduct annual financial audits of the outsourcer.
- B.Require the outsourcer to obtain ISO 27001 certification.
- ✓ C.Establish a service level agreement (SLA) with key performance indicators (KPIs).
- D.Allow the outsourcer to manage all security controls independently.
Why C: Establishing an SLA with KPIs is a fundamental governance practice for outsourcing because it defines measurable performance expectations and provides a basis for monitoring and enforcing the provider's obligations. It ensures the outsourcer is accountable for service delivery and aligns with business objectives.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.