Courseiva

CISA Governance and Management of IT Practice Question

A financial services firm has a mature IT governance framework. The IS auditor is reviewing the IT governance structure and notices that the IT steering committee meets quarterly and focuses primarily on project approvals. Which of the following is the MOST significant concern regarding this committee's effectiveness?

⚠ Common exam trap

The trap here is focusing on meeting frequency or representation as the primary issue, when the real problem is the committee's limited scope of responsibilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The committee's scope is too narrow to provide comprehensive IT governance oversight.

The most significant concern is that the IT steering committee's scope is too narrow, focusing only on project approvals. Effective IT governance requires oversight of strategic alignment, risk management, resource allocation, and performance. A committee that limits itself to project approvals fails to address these critical areas, leaving the organization exposed to unmanaged risks and misaligned IT investments. Broadening the committee's mandate is essential for effective governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The committee's scope is too narrow to provide comprehensive IT governance oversight.

    Why this is correct

    An IT steering committee should oversee a broad range of IT governance matters, including strategic alignment, risk management, resource allocation, and performance monitoring. Focusing primarily on project approvals limits its ability to address other critical governance areas. This narrow scope can lead to unmanaged risks, misalignment with business strategy, and missed opportunities for value creation. The committee's effectiveness is significantly compromised if it does not cover the full spectrum of IT governance responsibilities.

  • ✗

    Project approvals should be delegated to the project management office.

    Why it's wrong here

    Delegating project approvals to the PMO might improve efficiency, but it does not address the core concern that the steering committee is not fulfilling its broader governance role. The committee should retain oversight of strategic projects while also addressing other governance areas. Delegation without broadening the committee's scope would not fix the underlying problem of ineffective governance. Thus, this is not the most significant concern.

  • ✗

    Quarterly meetings are too infrequent to approve projects in a timely manner.

    Why it's wrong here

    While meeting frequency can affect responsiveness, quarterly meetings are not inherently inadequate for a steering committee, especially if project approval demands are low. The more fundamental issue is the committee's narrow focus, not the meeting schedule. Many organizations successfully use quarterly meetings for strategic oversight. Therefore, this concern is less significant than the limited scope of the committee's responsibilities.

  • ✗

    The committee lacks representation from business unit leaders.

    Why it's wrong here

    The scenario does not state that business unit leaders are absent from the committee. Even if they were, the primary concern would still be the committee's narrow focus. Business representation is important for alignment, but without broad governance responsibilities, even a well-represented committee would be ineffective. The most significant issue is the limited scope, which directly undermines the committee's ability to govern IT comprehensively.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.