CISA Governance and Management of IT Practice Question
An organization has a policy that requires all IT projects to have a business case approved by the IT steering committee. The IS auditor discovers that a major infrastructure upgrade was initiated without an approved business case. Which of the following is the auditor's PRIMARY concern?
⚠ Common exam trap
The trap here is focusing on operational issues like budget or resources rather than the governance failure of initiating a project without proper justification and approval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The project may not deliver expected business value or align with strategic goals.
The primary concern is that without an approved business case, the project may not deliver expected business value or align with strategic goals. The business case is a key governance control that ensures IT investments are justified and prioritized. Its absence indicates a breakdown in project initiation governance, which could result in wasted resources and failure to achieve strategic objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The project may exceed its budget due to lack of financial oversight.
Why it's wrong here
Budget overruns are possible, but the absence of a business case means there is no baseline for expected costs and benefits. The more fundamental concern is that the project was not evaluated for strategic alignment and value. Financial oversight is a component, but the primary governance failure is the lack of formal approval based on a business case.
- ✗
The IT steering committee may not be aware of the project's progress.
Why it's wrong here
The committee's awareness is important, but the core issue is that the project bypassed the required approval process. Without a business case, the committee cannot make an informed decision. The lack of awareness is a symptom; the root concern is the absence of governance control over project initiation, which could lead to unvetted investments.
- ✓
The project may not deliver expected business value or align with strategic goals.
Why this is correct
The primary purpose of a business case is to justify the investment and ensure alignment with strategic objectives. Without an approved business case, the project lacks formal justification and may not deliver value. This is the most significant concern because it undermines governance and could lead to wasted resources and strategic misalignment.
- ✗
The project may not have sufficient technical resources allocated.
Why it's wrong here
Resource allocation is a project management concern, but it is not the primary governance issue. The absence of an approved business case means the project was not formally justified in terms of business need, costs, and benefits. Resource adequacy is secondary to ensuring that the project is strategically aligned and approved through proper governance channels.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.