Courseiva

CISA Governance and Management of IT Practice Question

An IS auditor is reviewing an organization's IT governance policies and finds that the IT strategy is updated annually, but there is no process to monitor external factors such as regulatory changes or emerging technologies. Which of the following is the MOST significant risk of this deficiency?

⚠ Common exam trap

The trap here is focusing on internal alignment or investment returns when the scenario explicitly points to external factors, making regulatory compliance the most direct and severe risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The organization may fail to comply with new regulations.

The most significant risk of not monitoring external factors is regulatory non-compliance. Regulations can change rapidly, and failure to detect and respond to them can result in legal penalties, fines, and reputational harm. The IT strategy must include a process for environmental scanning to identify regulatory updates and emerging technologies. Without this, the organization may inadvertently violate new laws or fall behind competitors. The auditor should recommend implementing a formal external monitoring process as part of IT governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IT investments may not deliver expected returns.

    Why it's wrong here

    While poor monitoring of external factors could lead to suboptimal investment decisions, the scenario does not directly link the deficiency to investment returns. The primary risk is the failure to detect regulatory changes and emerging technologies that could render current investments obsolete or non-compliant. Investment returns are influenced by many factors, and the lack of external monitoring is more directly tied to compliance and strategic responsiveness. Thus, this option is less specific and less critical than the compliance risk.

  • ✓

    The organization may fail to comply with new regulations.

    Why this is correct

    Without monitoring regulatory changes, the organization may not be aware of new compliance requirements, leading to legal penalties, fines, and reputational damage. This is a direct and significant risk because regulatory compliance is mandatory. The IT strategy should include processes to scan the external environment for regulatory updates and adjust IT controls accordingly. The auditor should identify this as a critical deficiency because non-compliance can have severe financial and operational consequences, and it undermines the effectiveness of IT governance.

  • ✗

    The IT steering committee may not meet regularly.

    Why it's wrong here

    The scenario does not mention the IT steering committee's meeting frequency. The deficiency is about the absence of a process to monitor external factors, not about committee meetings. While regular meetings are important for governance, they are not the direct risk here. The auditor should focus on the specific gap: the lack of environmental scanning, which can lead to missed regulatory changes and technological shifts. This option is unrelated to the described deficiency.

  • ✗

    The IT strategy may become misaligned with business objectives.

    Why it's wrong here

    While misalignment with business objectives is a risk, the scenario specifically highlights the lack of monitoring of external factors. Business objectives can also change, but the absence of external monitoring directly affects the organization's ability to respond to regulatory and technological changes. The most significant risk is not internal misalignment but the failure to adapt to external shifts that could impact compliance and competitiveness. Therefore, this option, while plausible, is not the most critical.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.