CISA Governance and Management of IT Practice Question
An IS auditor is reviewing the IT governance framework of a small organization. The auditor finds that the IT manager reports directly to the CFO, and there is no separate IT steering committee. Which of the following is the MOST appropriate conclusion?
⚠ Common exam trap
The trap here is assuming that a formal IT steering committee and a specific reporting line are mandatory for all organizations, regardless of size or context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The governance structure may be appropriate for the organization's size, provided IT decisions are aligned with business strategy.
The most appropriate conclusion is that the governance structure may be appropriate for the organization's size, provided IT decisions are aligned with business strategy. Smaller organizations often rely on informal governance mechanisms rather than formal committees. The reporting line to the CFO can be effective if it facilitates strategic alignment and oversight. The auditor should focus on whether the structure achieves governance objectives, not on prescriptive best practices that may not fit the context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IT manager should report to the COO to ensure operational alignment.
Why it's wrong here
Reporting to the COO might improve operational alignment, but it is not inherently superior to reporting to the CFO. The appropriate reporting line depends on the organization's structure and priorities. The scenario does not provide evidence that operational alignment is lacking. This recommendation is prescriptive and not based on identified risks or deficiencies.
- ✗
The governance structure is inadequate because IT should report to the CEO.
Why it's wrong here
Reporting lines can vary based on organizational size, culture, and industry. In many organizations, IT reporting to the CFO is acceptable, especially if IT is viewed as a support function. The absence of a separate IT steering committee does not automatically make the structure inadequate. This conclusion is too prescriptive and does not consider the organization's context.
- ✗
The lack of an IT steering committee is a critical deficiency that must be remediated immediately.
Why it's wrong here
While an IT steering committee can be beneficial, its absence is not automatically a critical deficiency, especially in a small organization. Other mechanisms, such as regular management meetings or direct reporting to the CFO, may provide sufficient oversight. Calling it critical without considering compensating controls or the organization's size is an overreaction and not supported by the scenario.
- ✓
The governance structure may be appropriate for the organization's size, provided IT decisions are aligned with business strategy.
Why this is correct
In smaller organizations, formal IT steering committees may not be necessary if there is effective communication and alignment between IT and business leadership. The key is whether IT decisions support business objectives. The reporting line to the CFO can be effective if it ensures IT is integrated with financial and strategic planning. This conclusion is balanced and recognizes that governance structures should fit the organization's context.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.