Courseiva

CISA Governance and Management of IT Practice Question

A mid-sized insurance company has decided to adopt a formal IT governance framework because its board is concerned about unmanaged IT risk. The CIO asks the IS auditor to recommend the FIRST step in establishing the governance framework. Which of the following should the IS auditor recommend?

⚠ Common exam trap

The trap here is assuming that implementing a governance mechanism such as a steering committee or scorecard is the first step, when actually defining objectives and strategic alignment must come first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define IT governance objectives and align them with enterprise strategic goals.

The first step in establishing IT governance is to define objectives that align IT with enterprise strategy. This ensures that all subsequent governance structures, processes, and metrics are purposeful and support business goals. Without this alignment, other activities such as scorecards, RACI matrices, or steering committees lack a foundation and may not effectively manage IT-related risks or deliver value to the organization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a RACI matrix for all IT processes to clarify accountability.

    Why it's wrong here

    A RACI matrix is an effective tool for clarifying roles and responsibilities once governance structures and processes are designed. However, creating it as the first step assumes that the processes and objectives are already understood. Without defined objectives and alignment to strategy, the RACI matrix may assign responsibilities for activities that do not support the enterprise's goals, leading to inefficiency and potential misalignment.

  • ✓

    Define IT governance objectives and align them with enterprise strategic goals.

    Why this is correct

    Establishing IT governance must begin by defining clear objectives that are directly linked to the enterprise's strategic goals. Without this alignment, subsequent structures, processes, and metrics lack direction and may not deliver value. This foundational step ensures that governance efforts focus on achieving business outcomes and managing IT-related risks in a way that supports the organization's overall mission and stakeholder expectations.

  • ✗

    Implement a balanced scorecard to measure IT performance across four perspectives.

    Why it's wrong here

    A balanced scorecard is a valuable performance measurement tool, but it is a mechanism for monitoring and reporting, not the initial step in building a governance framework. Deploying it before objectives and alignment are defined would measure the wrong things and could misdirect resources. The scorecard should be derived from established objectives, making it a later, supporting activity rather than the first action.

  • ✗

    Establish an IT steering committee to oversee IT investment decisions.

    Why it's wrong here

    An IT steering committee is a key governance mechanism for overseeing IT investments and priorities, but it is a structural component that should be established after governance objectives and alignment are defined. Forming the committee first may result in oversight without clear direction, and its decisions may lack the strategic context needed to prioritize IT initiatives effectively. It follows, rather than precedes, objective setting.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.