hardMultiple Choice
CISA Practice Question: An auditor is reviewing IT policy compliance and…
An auditor is reviewing IT policy compliance and finds that a critical policy was last updated three years ago. The organization has undergone significant changes. What is the auditor's PRIMARY concern?
⚠ Common exam trap
CISA often tests root-cause prioritization — candidates pick awareness or enforcement because those sound like common audit findings, but the primary concern is strategic alignment of the policy content itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy may not be aligned with current business objectives
The primary concern with a policy that has not been updated for three years amid significant organizational change is that it may no longer align with current business objectives, risks, and operating environment. Policy relevance is the root issue; awareness, approval, and enforcement are downstream symptoms that may or may not exist. An outdated policy can direct behavior toward obsolete goals and create compliance gaps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Employees may not be aware of the policy
Why it's wrong here
Awareness is an operational communication issue, not the primary concern when the policy itself predates significant organisational change. The content may no longer match the current environment, so employees could be following obsolete rules. Awareness is tempting because it is a frequent policy-compliance finding, but it presupposes the policy is still valid.
- ✗
The policy may not have been approved by management
Why it's wrong here
Management approval is a one-off governance act; a three-year-old policy can still be approved. The real risk is that the policy no longer reflects the reorganised environment, so its controls may be obsolete. Approval status is tempting because unsigned policies are a common audit finding, but staleness against change is the concern here.
- ✗
The policy may not be enforced
Why it's wrong here
Enforcement concerns whether the policy is applied, not whether its content remains valid after three years of organisational change. A stale policy may mandate controls that no longer fit the environment. Enforcement is tempting because non-compliance is a common audit issue, but the stem's emphasis on significant change points to relevance, not application.
- ✓
The policy may not be aligned with current business objectives
Why this is correct
Significant organisational change can render a three-year-old policy misaligned with current business objectives, so the auditor's primary concern is that the policy no longer reflects what the organisation now needs to achieve. This addresses the stem's compliance concern directly: outdated policy content, not merely its review date or approval status.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.