Courseiva

CISA Governance and Management of IT Practice Question

An IS auditor is reviewing the governance structure of a large retail company. The board has delegated all IT oversight to the IT steering committee, which meets quarterly and focuses primarily on project prioritization. The auditor notes that the board receives no IT-related reports and does not review IT risks. Which of the following is the MOST significant governance concern?

⚠ Common exam trap

The trap here is assuming that delegating IT oversight to a committee absolves the board of responsibility, when in fact the board must still provide direction and monitor IT risks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The board has not retained ultimate responsibility for IT governance and oversight.

The board retains ultimate accountability for IT governance and must ensure oversight, even when delegating to committees. Without board-level reporting and risk review, the governance structure lacks direction and accountability, increasing the risk of IT failures and misalignment with business objectives. Other concerns, such as meeting frequency or committee focus, are secondary to this foundational failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    There is no independent assurance over IT activities reported to the board.

    Why it's wrong here

    The absence of independent assurance is a control gap, but it is not the most critical issue here. The board receives no IT reports at all, so assurance would be moot. The fundamental problem is that the board has not established a governance framework that includes reporting and risk oversight. Assurance is a component, not the root cause.

  • ✗

    The IT steering committee is too focused on project prioritization and ignores other IT domains.

    Why it's wrong here

    A narrow focus on project prioritization is a weakness, but it is secondary to the board's lack of involvement. The committee's scope can be expanded, but if the board does not provide direction and oversight, even a well-rounded committee may lack authority and alignment with enterprise goals. The primary failure is at the board level.

  • ✗

    The IT steering committee meets only quarterly, which is insufficient to address emerging IT risks.

    Why it's wrong here

    While quarterly meetings may be infrequent for dynamic IT risks, the core issue is not the frequency but the board's complete abdication of IT oversight. Even with frequent meetings, if the board does not fulfill its governance responsibilities, the governance structure remains deficient. The committee's meeting schedule is a symptom, not the root cause.

  • ✓

    The board has not retained ultimate responsibility for IT governance and oversight.

    Why this is correct

    The board is ultimately accountable for IT governance, even when delegating to committees. By receiving no IT reports and not reviewing IT risks, the board has failed to exercise its oversight role. This is the most significant concern because it undermines the entire governance framework and can lead to unmanaged IT risks and misalignment with business strategy.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.