hardMultiple ChoiceObjective-mapped
CISA Practice Question: A large financial institution is implementing a…
A large financial institution is implementing a new core banking system to replace a legacy system. The project has been underway for 18 months and is behind schedule. User acceptance testing (UAT) has revealed significant data integrity issues, including missing customer records and incorrect interest calculations. The project manager, under pressure from senior management to meet a regulatory deadline, proposes going live with a promise to fix the issues in a post-implementation phase. The development team has been making ad hoc code changes directly in the test environment without version control or proper testing. Additionally, the IS auditor discovers that the business requirements were never formally signed off by the user community; only verbal approvals were obtained. The project has consumed 90% of the budget but only 60% of the functionality is tested. Which of the following is the BEST course of action for the IS auditor to recommend?
⚠ Common exam trap
A common mix-up: candidates choose Option A because they think a post-implementation support plan is a pragmatic compromise, but the CISA exam emphasizes that going live with unresolved critical defects and uncontrolled code changes violates fundamental SDLC controls and ISACA's IS acquisition and implementation standards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Recommend halting the go-live until the business requirements are formally signed off and UAT is completed successfully with all critical defects resolved.
The project lacks formal sign-off on business requirements, has unresolved critical data integrity issues, and has been making uncontrolled code changes without version control. Going live under these conditions would violate ISACA's IS acquisition and implementation standards, which require that all critical defects be resolved and UAT be successfully completed before production deployment. The regulatory deadline does not justify bypassing these fundamental controls, as post-implementation fixes cannot guarantee data integrity and could lead to regulatory penalties.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow the go-live with a formal post-implementation support plan and a dedicated team to address defects.
Why it's wrong here
This accepts the risk of data integrity failures and untested functionality, which could lead to regulatory penalties and financial loss.
- ✓
Recommend halting the go-live until the business requirements are formally signed off and UAT is completed successfully with all critical defects resolved.
Why this is correct
This addresses root causes: lack of formal sign-off and unresolved defects, ensuring a controlled implementation.
- ✗
Suggest a phased go-live, releasing the tested modules to production while continuing development on the remaining modules.
Why it's wrong here
Data integrity issues are not limited to specific modules; phased deployment would still expose critical processes to risk.
- ✗
Escalate the issues to the board of directors and recommend immediate termination of the project.
Why it's wrong here
Termination is premature; the project can be remediated with proper controls and additional investment.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.