Courseiva

CISA Governance and Management of IT Practice Question

An IS auditor is assessing an organization's IT governance implementation. The auditor finds that IT policies are outdated, roles and responsibilities are unclear, and there is no regular reporting on IT performance to the board. Which TWO of the following are the MOST critical actions to improve IT governance? (Choose two.)

⚠ Common exam trap

The trap here is choosing tactical actions like updating policies or training, which are important but do not address the fundamental governance gaps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement regular IT performance reporting to the board and executive management.

The most critical actions are to establish a formal governance framework and implement regular reporting. These address the root causes: lack of structure and lack of oversight. A framework clarifies roles and responsibilities, while reporting ensures accountability and informed decision-making. Other actions, such as updating policies or training, are supportive but not sufficient alone.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the IT budget to allow for more staff training.

    Why it's wrong here

    Training is valuable, but it does not address the fundamental governance deficiencies of unclear roles and lack of reporting. Budget increases without governance improvements may not resolve accountability issues. The critical actions are structural and informational.

  • ✗

    Update all IT policies annually to ensure they reflect current technology.

    Why it's wrong here

    While updating policies is important, it is not the most critical action compared to establishing a governance framework and reporting. Policies are a component of governance, but without clear roles and reporting, updated policies may not be enforced. The root cause is the lack of governance structure.

  • ✓

    Implement regular IT performance reporting to the board and executive management.

    Why this is correct

    Regular reporting is essential for transparency and informed decision-making. It enables the board to monitor IT performance, risks, and alignment with strategy. Without reporting, governance is reactive and blind. This action directly addresses the lack of oversight and ensures accountability.

  • ✗

    Conduct an annual IT risk assessment to identify vulnerabilities.

    Why it's wrong here

    Risk assessments are important, but they are part of a broader governance framework. Without defined roles and reporting, risk assessment results may not be acted upon. The most critical actions are to establish governance structure and reporting mechanisms to ensure risks are managed.

  • ✓

    Establish a formal IT governance framework with defined roles and responsibilities.

    Why this is correct

    This is critical because unclear roles and responsibilities lead to accountability gaps. A formal framework, such as COBIT, provides structure for decision-making, risk management, and resource allocation. It ensures that IT activities are aligned with business goals and that oversight is systematic. Without this, governance remains ad hoc and ineffective.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.