CISA Governance and Management of IT Practice Question
An organization has decentralized IT management with each business unit making its own technology decisions. Which of the following is the BEST way to maintain enterprise-wide governance?
⚠ Common exam trap
CISA often tests governance models, and candidates may choose centralized approval or budgeting as the best way to maintain governance, but in a decentralized structure, a collaborative review board is more effective because it respects autonomy while ensuring alignment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establish an enterprise architecture review board with representatives from all business units.
Establishing an enterprise architecture review board with representatives from all business units is the best way to maintain enterprise-wide governance in a decentralized IT management structure. This board provides a collaborative forum where business units can align their technology decisions with enterprise-wide standards and strategic goals, ensuring consistency and compliance without centralizing decision-making. It balances autonomy with governance by involving stakeholders from all units in the review and approval of architectural decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy a single enterprise resource planning (ERP) system across all units.
Why it's wrong here
A single ERP standardises transaction processing and data, but enterprise-wide governance requires decision rights, policies and oversight spanning all technology domains, not one application. ERP deployment is the correct response when the goal is integrated financial and operational data across units, not governance itself.
- ✗
Require all IT projects to be approved by the corporate IT department.
Why it's wrong here
Corporate approval gates each project individually but sets no reusable enterprise standards, so units still choose incompatible platforms between reviews. It is tempting because central approval is genuinely effective when the risk is isolated, high-cost procurements needing executive sign-off rather than ongoing architectural divergence.
- ✗
Create a central IT budget that allocates funds to business units.
Why it's wrong here
A central budget controls funding, not technology standards, so business units can still deploy non-compliant systems once allocated. It is tempting because centralised budgeting genuinely enforces financial oversight and cost accountability, which is the right answer when the governance gap is uncontrolled spend rather than divergent architecture.
- ✓
Establish an enterprise architecture review board with representatives from all business units.
Why this is correct
An enterprise architecture review board with representatives from every business unit provides a cross-unit forum that reviews technology decisions against shared standards. This preserves enterprise-wide governance without removing the decentralised autonomy each unit currently exercises.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is considering restructuring its IT department from a centralized to a decentralized model to give business units more autonomy. What is a PRIMARY governance risk associated with this move?
medium- A.Difficulty in managing vendor contracts due to decentralization.
- B.Reduced innovation due to lack of central coordination.
- C.Increased risk of project cost overruns.
- ✓ D.Inconsistent IT policies and security controls across business units.
Why D: Decentralizing IT gives business units autonomy, but the primary governance risk is that each unit may adopt its own policies, standards, and security controls. This fragmentation leads to inconsistent security postures, compliance gaps, and difficulty enforcing enterprise-wide governance. The core risk is loss of centralized control over policy and security consistency.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.