A multinational corporation is implementing a global IT governance framework. Which of the following challenges is MOST likely to arise?
Differing data protection, privacy, and financial reporting rules across jurisdictions force the framework to reconcile incompatible mandates, which is the central governance obstacle. A single global policy cannot satisfy every regulator simultaneously, so conflicting requirements are the most likely challenge.
Why this answer
A global IT governance framework must reconcile laws, regulations, and industry standards across many jurisdictions. Multinationals face conflicting requirements — for example, GDPR data residency in the EU versus data localization laws in other countries, or differing breach-notification timelines. These conflicts directly shape governance policies, controls, and reporting, making them the most likely and most impactful challenge.
Exam trap
The trap is selecting an operational or financial issue (hardware, training, licensing) when the question asks about governance — CISA expects you to recognize that governance challenges are regulatory and strategic, not tactical.
How to eliminate wrong answers
Option B is wrong because hardware standardization is an operational/engineering task, not a governance challenge, and it is usually solvable with procurement standards. Option C is wrong because user training is a routine change-management activity, not a structural governance conflict. Option D is wrong because software licensing costs are a financial/procurement concern, not a governance framework challenge.