Courseiva

CISA Governance and Management of IT Practice Question

An IS auditor is evaluating an organization's IT governance framework. The auditor finds that IT decisions are made ad hoc by various business units without alignment to corporate strategy. Which TWO of the following are the MOST important governance mechanisms the auditor should recommend to address this issue? (Choose two.)

⚠ Common exam trap

The trap here is focusing on reactive or structural changes like increasing budget or centralizing authority, which do not address the need for ongoing strategic alignment and cross-functional governance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establish an IT steering committee with representation from key business units and IT.

The lack of alignment and ad hoc decision-making indicates a need for governance structures that provide direction and oversight. An IT steering committee and formal portfolio management are proactive mechanisms that ensure IT initiatives are prioritized and aligned with corporate strategy. They establish accountability and cross-functional collaboration, directly addressing the root cause.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Establish an IT steering committee with representation from key business units and IT.

    Why this is correct

    An IT steering committee provides a formal forum for prioritizing IT initiatives, aligning them with business strategy, and ensuring cross-functional input. It directly addresses the lack of coordination and strategic alignment by centralizing decision-making and fostering communication between business and IT. This is a fundamental governance mechanism to prevent ad hoc decisions.

  • ✓

    Implement a formal IT project portfolio management process.

    Why this is correct

    IT project portfolio management ensures that all IT investments are evaluated, prioritized, and monitored against strategic objectives. It provides a structured approach to selecting and managing projects, reducing ad hoc decisions and resource waste. This mechanism directly addresses the issue by enforcing alignment and transparency in IT investment decisions.

  • ✗

    Increase the IT budget to allow business units more autonomy.

    Why it's wrong here

    Increasing the budget without governance controls would likely exacerbate the problem by funding more uncoordinated initiatives. Autonomy without alignment can lead to duplication, wasted resources, and further divergence from corporate strategy. The issue is not funding but lack of governance; more money does not solve the root cause.

  • ✗

    Delegate all IT decisions to the CIO to centralize authority.

    Why it's wrong here

    Centralizing all decisions with the CIO may improve coordination but can reduce business unit buy-in and responsiveness. It does not inherently ensure alignment with corporate strategy unless accompanied by governance structures like a steering committee. Moreover, it may not address the need for cross-functional input and could create new bottlenecks.

  • ✗

    Conduct annual IT audits to identify misalignments.

    Why it's wrong here

    Annual audits are detective and periodic, not preventive governance mechanisms. They can identify issues after they occur but do not provide ongoing direction or decision-making structure. While valuable, audits alone do not establish the necessary governance to align IT decisions with strategy; proactive mechanisms like steering committees and portfolio management are needed.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.