hardMultiple Select
CISA Practice Question: An IS auditor is assessing the effectiveness of…
An IS auditor is assessing the effectiveness of an organization's IT governance framework. Which THREE of the following are key indicators of a mature governance process?
⚠ Common exam trap
The trap here is that candidates often mistake basic financial oversight (annual budget approval) for a sign of governance maturity, when in reality mature governance requires continuous monitoring, defined decision rights, and performance measurement beyond periodic approvals.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defined roles and responsibilities for IT decisions
Option A is correct because a mature IT governance framework requires clearly defined roles and responsibilities (e.g., RACI matrices) that specify who is accountable for IT decision-making, ensuring ownership and reducing ambiguity. Option C is correct because an IT steering committee provides the formal governance structure through which senior business and IT leaders prioritize investments, align IT with business strategy, and oversee risk—a hallmark of mature governance such as that described in COBIT's EDM and APO domains. Option E is correct because regular measurement of IT performance against defined metrics (e.g., KPIs/KGIs, balanced scorecard) enables continuous monitoring, accountability, and improvement, which is essential for governance maturity. Option B is not a key indicator because an annual budget approval is a routine financial control and does not by itself demonstrate mature governance processes such as decision rights, oversight structures, or performance measurement. Option D is not a key indicator because outsourcing all IT operations is a sourcing decision, not evidence of governance maturity, and could even weaken governance if oversight is not retained.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Defined roles and responsibilities for IT decisions
Why this is correct
Clearly defined roles and responsibilities establish accountability for IT decisions, ensuring governance is not ad hoc. This directly satisfies the stem's demand for a maturity indicator, as documented decision rights are a recognised hallmark of effective IT governance frameworks.
- ✗
Annual IT budget approval by senior management
Why it's wrong here
Annual budget approval is a basic fiduciary routine, not evidence of mature governance; maturity requires continuous portfolio oversight, risk reporting and performance measurement. Budget approval would suffice only where governance is entirely absent and no other oversight mechanism exists.
- ✓
Existence of an IT steering committee
Why this is correct
An IT steering committee provides cross-functional oversight of IT investment and priorities, evidencing formal governance structures rather than informal arrangements. Its existence directly satisfies the stem's criterion for a maturity indicator within the organisation's IT governance framework.
- ✗
Outsourcing of all IT operations
Why it's wrong here
Outsourcing all IT operations transfers control to third parties and weakens governance accountability, so it signals immaturity rather than maturity. Outsourcing suits cost reduction or access to specialist capability, but governance maturity demands retained oversight, vendor risk management and internal accountability.
- ✓
Regular measurement of IT performance against metrics
Why this is correct
Regular measurement of IT performance against metrics demonstrates a mature governance process because it provides objective evidence that IT activities align with business objectives and that management monitors outcomes continuously. This satisfies the stem's requirement for key maturity indicators, distinguishing mature governance from ad hoc oversight through quantifiable, repeatable performance evaluation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.