mediumMultiple Choice
CISA Practice Question: Is adopting a decentralized IT structure to…
An organization is adopting a decentralized IT structure to better meet the needs of its business units. Which of the following is a potential risk of this approach?
⚠ Common exam trap
CISA often tests the trade-off between centralization and decentralization, and candidates frequently confuse the risks of one with the benefits of the other—picking 'slower response' as a risk of decentralization when it is actually a risk of centralization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increased duplication of IT resources and inconsistent standards
Decentralized IT structures push decision-making authority and resources down to individual business units, which naturally leads to each unit acquiring its own hardware, software, and support staff. This fragmentation creates redundant systems and divergent technical standards across the organization, increasing cost and complexity. The correct answer captures this classic trade-off: while decentralization improves responsiveness, it sacrifices economies of scale and standardization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Increased duplication of IT resources and inconsistent standards
Why this is correct
Decentralised IT lets each business unit procure and configure independently, so overlapping systems and divergent configurations emerge across units. This directly satisfies the stem's risk: duplicated IT resources alongside inconsistent standards, raising cost and complicating governance, integration and security enforcement.
- ✗
Slower response to business unit needs
Why it's wrong here
Decentralisation places IT decision-making and resources within business units, which typically shortens response times by removing central approval queues. It is tempting because centralised structures genuinely can respond slowly, but the stem asks for a risk of decentralising, and this describes the problem decentralisation is adopted to solve.
- ✗
Higher initial setup costs for central services
Why it's wrong here
Decentralisation shifts spend toward business-unit systems and duplicated local infrastructure, so central service setup costs do not rise as a consequence. It is tempting because centralising shared services does carry significant initial build costs, but that describes the centralised model, not the risk introduced by moving away from it.
- ✗
Reduced alignment with corporate strategy
Why it's wrong here
Decentralised structures typically improve business-unit responsiveness but weaken enterprise-wide governance and standardisation, not corporate strategy alignment directly. It is tempting because decentralisation does dilute central control, yet the concrete risk is duplicated resources and inconsistent standards rather than strategic misalignment.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.