CISA Governance and Management of IT Practice Question
An IS auditor is reviewing an organization's IT governance framework and notices that the IT steering committee, chaired by the CIO, approves all IT investments and also monitors their benefits realization. The board has delegated full IT decision-making authority to this committee. The auditor is MOST likely to conclude that:
⚠ Common exam trap
The trap here is assuming that regular reporting to the board or the CIO's technical expertise can compensate for the lack of independent oversight in a self-review situation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The committee's dual role of approving investments and monitoring benefits creates a self-review risk that weakens independent oversight.
The IT steering committee, led by the CIO, both approves IT investments and monitors their benefits, which is a self-review conflict. The board has delegated full authority, meaning it lacks independent oversight. Effective IT governance requires separation between those who make investment decisions and those who evaluate their outcomes. The auditor should conclude that this structure weakens independent oversight and may lead to biased benefits assessments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The arrangement is appropriate as long as the committee reports regularly to the board on its decisions and outcomes.
Why it's wrong here
Regular reporting to the board is a good practice, but it does not address the fundamental conflict of interest where the CIO-chaired committee both approves investments and monitors their benefits. The board has delegated full decision-making authority, which means it has not retained sufficient oversight to challenge or independently evaluate the committee's decisions. Reporting alone does not provide independent assurance.
- ✗
The committee structure provides adequate oversight because the CIO has the technical expertise to evaluate IT investments.
Why it's wrong here
While the CIO's technical expertise is valuable, the committee's composition and mandate create a conflict of interest. The same body that proposes and approves IT investments should not be solely responsible for monitoring their benefits, as this reduces independent scrutiny. The board's delegation of full authority without retained oversight weakens governance. Expertise alone does not mitigate the structural risk of self-review.
- ✗
The board's delegation of full authority to the committee is acceptable because IT governance is an operational responsibility, not a board responsibility.
Why it's wrong here
IT governance is a board-level responsibility. While the board can delegate certain decision-making to management, it cannot abdicate its oversight role. The board must retain accountability for ensuring IT supports business objectives and managing IT-related risks. Delegating full authority without retained oversight violates governance principles, as the board remains ultimately responsible.
- ✓
The committee's dual role of approving investments and monitoring benefits creates a self-review risk that weakens independent oversight.
Why this is correct
The IT steering committee, chaired by the CIO, both approves investments and monitors their benefits realization. This self-review creates a conflict of interest because the same group evaluates the success of its own decisions. Effective governance requires independent oversight, typically by the board or a separate audit function, to ensure objective assessment. The auditor should flag this as a governance weakness.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.