Courseiva

CISA Governance and Management of IT Practice Question

An IS auditor is reviewing the organization's IT governance framework. The board has delegated oversight of IT to an IT steering committee. The auditor finds that the committee meets quarterly, but its charter does not define decision rights or escalation procedures. Which of the following is the MOST significant concern?

⚠ Common exam trap

The trap here is assuming that meeting frequency or committee composition is the primary governance issue, when the absence of decision rights and escalation procedures is the fundamental flaw.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The committee's charter lacks clear decision rights and escalation procedures, creating ambiguity in IT decision-making.

The most significant concern is the lack of defined decision rights and escalation procedures in the committee's charter. Effective IT governance requires clear authority for decision-making and a defined path for escalating issues. Without these, the committee cannot ensure timely, accountable IT decisions, leading to potential misalignment with business objectives and unmanaged risks. Meeting frequency and representation are secondary to this structural gap.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The board has delegated IT oversight to a committee, which dilutes board accountability.

    Why it's wrong here

    Delegating IT oversight to a committee is a common and acceptable governance practice, provided the committee has a clear mandate and reporting lines. The board retains ultimate accountability, but delegation does not inherently dilute it. The real issue is the committee's incomplete charter, not the delegation itself. This option misidentifies the root cause of the governance weakness.

  • ✗

    The committee meets too infrequently to govern IT effectively.

    Why it's wrong here

    Meeting frequency alone is not the primary governance deficiency. While quarterly meetings may be insufficient for some organizations, the lack of defined decision rights and escalation procedures creates ambiguity about who can make IT decisions and how issues are escalated, which undermines accountability and can lead to delays or unauthorized actions. The frequency issue is secondary to the structural gap in the charter.

  • ✗

    The committee does not include business unit representatives, limiting its perspective.

    Why it's wrong here

    While business representation is valuable, the scenario does not state that business units are excluded. Even if they were, the absence of defined decision rights and escalation procedures is a more fundamental deficiency that affects the committee's ability to function. This option assumes a fact not given and addresses a secondary concern rather than the critical governance gap.

  • ✓

    The committee's charter lacks clear decision rights and escalation procedures, creating ambiguity in IT decision-making.

    Why this is correct

    This is the most significant concern because without defined decision rights and escalation procedures, the committee cannot effectively govern IT. Decision rights clarify who is authorized to make specific IT decisions, while escalation procedures ensure issues are raised to the appropriate level. Their absence can lead to inconsistent decisions, unmanaged risks, and accountability gaps, directly undermining the governance framework.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.