CISA Governance and Management of IT Practice Question
A retail organization's board has approved an IT governance framework that delegates decision rights for infrastructure standards to a central architecture board, while reserving funding decisions above a threshold for the board's technology committee. Business units must comply with the standards but may request exceptions. Which of the following is the MOST important control for the IS auditor to verify when assessing the effectiveness of this framework?
⚠ Common exam trap
The trap here is focusing on the visible activity of the governance bodies rather than on the exception mechanism that determines whether their decision rights are real.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exception requests are documented, time-bound, and approved at a level commensurate with the risk of noncompliance.
Governance frameworks allocate decision rights, but their effectiveness is determined by how deviations are handled. Because business units can request exceptions to architecture standards, the exception process is where delegated authority is either preserved or eroded. Documented, time-bound exceptions approved at a risk-commensurate level preserve the architecture board's authority while allowing justified flexibility. Meeting cadence, satisfaction surveys, and budget review do not test whether standards are actually binding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The architecture board meets at least quarterly and maintains minutes of its deliberations.
Why it's wrong here
Meeting frequency and minutes indicate that the board is active, but they do not demonstrate that its decisions are enforced or that deviations are controlled. A board could meet regularly and still preside over widespread noncompliance. While documentation is useful evidence, it is a weaker control than the exception management process that determines whether the standards actually bind the organization.
- ✓
Exception requests are documented, time-bound, and approved at a level commensurate with the risk of noncompliance.
Why this is correct
The framework's credibility depends on whether the delegated authority is actually enforced. Exceptions are the primary leak path: if they are undocumented, open-ended, or approved at too low a level, the architecture board's decision rights become nominal. Verifying that exceptions are documented, time-bound, and approved commensurate with risk directly tests whether the governance design operates as intended in practice.
- ✗
The board's technology committee reviews the IT capital budget at each scheduled meeting.
Why it's wrong here
Budget review exercises the funding decision right reserved to the technology committee, but it does not test the infrastructure standards decision right delegated to the architecture board. The scenario's central risk is noncompliance with standards, which budget review would not detect. This control addresses a different part of the framework and leaves the most likely failure mode unexamined.
- ✗
Business units are surveyed annually on their satisfaction with the standards and the exception process.
Why it's wrong here
Satisfaction surveys capture perceptions, not compliance. A business unit could report high satisfaction while quietly deploying nonstandard technology. Survey results are subjective and easily influenced by factors unrelated to control effectiveness. This evidence does not establish whether decision rights are respected, whether exceptions are controlled, or whether the framework achieves its intended governance outcomes.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.