Courseiva

CISA Governance and Management of IT Practice Question

A retail organization's board has approved an IT governance framework that delegates decision rights for infrastructure standards to a central architecture board, while reserving funding decisions above a threshold for the board's technology committee. Business units must comply with the standards but may request exceptions. Which of the following is the MOST important control for the IS auditor to verify when assessing the effectiveness of this framework?

⚠ Common exam trap

The trap here is focusing on the visible activity of the governance bodies rather than on the exception mechanism that determines whether their decision rights are real.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exception requests are documented, time-bound, and approved at a level commensurate with the risk of noncompliance.

Governance frameworks allocate decision rights, but their effectiveness is determined by how deviations are handled. Because business units can request exceptions to architecture standards, the exception process is where delegated authority is either preserved or eroded. Documented, time-bound exceptions approved at a risk-commensurate level preserve the architecture board's authority while allowing justified flexibility. Meeting cadence, satisfaction surveys, and budget review do not test whether standards are actually binding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The architecture board meets at least quarterly and maintains minutes of its deliberations.

    Why it's wrong here

    Meeting frequency and minutes indicate that the board is active, but they do not demonstrate that its decisions are enforced or that deviations are controlled. A board could meet regularly and still preside over widespread noncompliance. While documentation is useful evidence, it is a weaker control than the exception management process that determines whether the standards actually bind the organization.

  • ✓

    Exception requests are documented, time-bound, and approved at a level commensurate with the risk of noncompliance.

    Why this is correct

    The framework's credibility depends on whether the delegated authority is actually enforced. Exceptions are the primary leak path: if they are undocumented, open-ended, or approved at too low a level, the architecture board's decision rights become nominal. Verifying that exceptions are documented, time-bound, and approved commensurate with risk directly tests whether the governance design operates as intended in practice.

  • ✗

    The board's technology committee reviews the IT capital budget at each scheduled meeting.

    Why it's wrong here

    Budget review exercises the funding decision right reserved to the technology committee, but it does not test the infrastructure standards decision right delegated to the architecture board. The scenario's central risk is noncompliance with standards, which budget review would not detect. This control addresses a different part of the framework and leaves the most likely failure mode unexamined.

  • ✗

    Business units are surveyed annually on their satisfaction with the standards and the exception process.

    Why it's wrong here

    Satisfaction surveys capture perceptions, not compliance. A business unit could report high satisfaction while quietly deploying nonstandard technology. Survey results are subjective and easily influenced by factors unrelated to control effectiveness. This evidence does not establish whether decision rights are respected, whether exceptions are controlled, or whether the framework achieves its intended governance outcomes.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.