CISA Governance and Management of IT Practice Question
A hospital's IT department has implemented a new electronic health record (EHR) system. The IS auditor is reviewing the IT governance over the project and finds that the project sponsor is the CIO, who also chairs the IT steering committee that approved the project. Which of the following is the MOST significant governance risk?
⚠ Common exam trap
The trap here is focusing on the CIO's technical knowledge or the sponsor's role, rather than recognizing the conflict of interest created by combining sponsorship and approval responsibilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Lack of segregation of duties between project sponsorship and project approval.
The most significant governance risk is the lack of segregation of duties between project sponsorship and project approval. When the CIO sponsors the project and also chairs the committee that approves it, independent oversight is compromised. This can lead to inadequate challenge, biased decision-making, and insufficient risk assessment. Proper governance requires that project approval be made by a body that can objectively evaluate the project's merits and risks, separate from those advocating for it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Lack of segregation of duties between project sponsorship and project approval.
Why this is correct
Having the CIO serve as both project sponsor and chair of the committee that approves the project creates a conflict of interest and a lack of segregation of duties. The sponsor is responsible for advocating for the project, while the approval body should provide independent oversight. This combination can lead to biased decisions, insufficient challenge, and inadequate risk assessment. It undermines the governance principle of independent review and can result in projects proceeding without proper scrutiny.
- ✗
The project sponsor should be a clinical leader rather than the CIO.
Why it's wrong here
While clinical involvement is important for an EHR project, the choice of sponsor is not inherently a governance risk as long as proper oversight exists. The critical issue is that the same person sponsors and approves the project, creating a conflict. The sponsor's functional background is secondary to the need for independent approval. Thus, this is not the most significant governance risk.
- ✗
The IT steering committee may not have the authority to approve large projects.
Why it's wrong here
The scenario does not suggest that the committee lacks authority; it states that the committee approved the project. The governance risk lies in the CIO's dual role, not in the committee's authority. If the committee lacked authority, that would be a separate issue, but here the problem is the lack of independent review due to the CIO's involvement in both sponsorship and approval. Therefore, this is not the most significant risk.
- ✗
The CIO may not have sufficient technical knowledge to sponsor an EHR project.
Why it's wrong here
The scenario does not indicate that the CIO lacks technical knowledge. Even if that were a concern, it is not a governance risk of the same magnitude as a lack of segregation of duties. Sponsorship requires leadership and business acumen more than deep technical expertise. The primary governance issue is the dual role that compromises independent oversight, not the CIO's technical competence.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.