CISA Governance and Management of IT Practice Question
An IS auditor is assessing the IT governance framework of a retail company. The auditor finds that the company has a formal IT strategy, an IT steering committee, and a defined IT organizational structure. However, the auditor notes that there is no process to ensure that IT investments are justified and prioritized. Which of the following are the MOST appropriate recommendations to address this deficiency? (Choose two.)
⚠ Common exam trap
The trap here is selecting actions that improve oversight frequency or delegate decisions, which do not establish a structured process for justifying and prioritizing investments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a formal IT investment approval process with defined criteria.
The most appropriate recommendations are to implement a formal IT investment approval process with defined criteria and to establish an IT portfolio management function. These two measures directly address the absence of a process to justify and prioritize IT investments. The approval process ensures that each investment is evaluated against consistent criteria, while portfolio management provides ongoing oversight and prioritization across all investments, aligning them with strategic objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a post-implementation review of all IT projects.
Why it's wrong here
Post-implementation reviews are valuable for assessing whether projects delivered expected benefits, but they are after-the-fact and do not ensure that investments are justified and prioritized before approval. While they can inform future decisions, they do not provide the upfront governance mechanism needed to address the deficiency. This option is a detective control, not a preventive one.
- ✗
Increase the frequency of IT steering committee meetings to monthly.
Why it's wrong here
Increasing meeting frequency may improve oversight but does not establish a process for justifying and prioritizing IT investments. Without defined criteria and a portfolio view, more frequent meetings may not lead to better investment decisions. This option addresses the symptom (lack of oversight) rather than the root cause (no investment justification process).
- ✓
Implement a formal IT investment approval process with defined criteria.
Why this is correct
A formal IT investment approval process with defined criteria (e.g., ROI, strategic alignment, risk) ensures that investments are justified and prioritized consistently. This directly addresses the deficiency of no process to justify and prioritize IT investments. It provides a structured mechanism for decision-making and accountability, which is essential for effective IT governance.
- ✓
Establish an IT portfolio management function to oversee investment prioritization.
Why this is correct
IT portfolio management provides a centralized view of all IT investments, enabling prioritization based on strategic value, risk, and resource constraints. This function helps ensure that investments are justified and aligned with business objectives. It complements a formal approval process by providing ongoing oversight and optimization of the IT investment portfolio, directly addressing the gap.
- ✗
Delegate investment decisions to individual business units to speed up approvals.
Why it's wrong here
Delegating investment decisions to business units without central oversight can lead to fragmentation, duplication, and misalignment with corporate strategy. It does not ensure that investments are justified and prioritized from an enterprise perspective. This option could exacerbate the problem by creating inconsistent decision-making and potential conflicts of interest.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.