CISA Governance and Management of IT Practice Question
An IS auditor is reviewing an organization's IT governance structure. The board of directors has delegated all IT oversight to the CIO, who reports to the CFO. The auditor finds that the board receives only annual summaries of IT performance and never reviews IT risks. Which of the following is the MOST significant governance concern?
⚠ Common exam trap
The trap here is assuming that delegating IT oversight to a capable CIO absolves the board of its governance responsibilities, when in fact the board must retain ultimate accountability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The board has not retained ultimate responsibility for IT oversight.
The board of directors holds ultimate accountability for IT governance, including oversight of IT risks and alignment with business strategy. Delegating all oversight to the CIO without active board involvement and only receiving annual summaries means the board is not fulfilling its fiduciary duty. This creates a significant governance risk because IT decisions may not be aligned with stakeholder interests and risks may go unaddressed. The auditor should highlight this as a critical concern.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The board has not retained ultimate responsibility for IT oversight.
Why this is correct
The board is ultimately responsible for IT governance, including risk oversight. By delegating all oversight to the CIO and only receiving annual summaries, the board has effectively abdicated its responsibility. This creates a governance gap where IT risks may not be adequately addressed at the highest level. The auditor should flag this as a significant deficiency because it undermines the principles of effective IT governance.
- ✗
The CFO should not have IT reporting to them because it creates a conflict of interest.
Why it's wrong here
While IT reporting to the CFO may not be ideal in all organizations, it is not inherently a conflict of interest. Many organizations have IT report to the CFO, and this structure can work if proper governance is in place. The more critical issue is the board's lack of active oversight, not the reporting line. The auditor should focus on the governance gap rather than the reporting structure.
- ✗
IT performance is not measured using balanced scorecard metrics.
Why it's wrong here
While balanced scorecard metrics can be useful, the scenario does not specify that they are required or that their absence is the most significant concern. The core issue is the board's limited involvement in IT risk oversight, not the specific measurement framework. The auditor's primary focus should be on governance effectiveness, which is compromised by the board's passive role.
- ✗
The CIO lacks the authority to implement IT strategies.
Why it's wrong here
The scenario does not indicate that the CIO lacks authority; the board has delegated all IT oversight to the CIO, which implies sufficient authority. The concern is not about the CIO's ability to act but about the lack of board-level oversight and accountability. Without board engagement, IT governance may not align with business objectives, but the CIO's authority itself is not the primary issue.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.