CISA Governance and Management of IT Practice Question
An organization is establishing an IT governance committee. The committee's charter includes overseeing IT investments, monitoring IT performance, and ensuring compliance with regulations. Which of the following should the IS auditor recommend as the MOST important characteristic of the committee's membership?
⚠ Common exam trap
The trap here is assuming that IT governance committees should be dominated by IT or finance experts, when effective governance requires cross-functional representation to align IT with business objectives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inclusion of senior business executives and the CIO
The most important characteristic of an IT governance committee is balanced membership that includes senior business executives and the CIO. This ensures that IT decisions are aligned with business strategy, risks are managed from both business and technical perspectives, and accountability is shared. Without business representation, IT may become isolated; without IT representation, decisions may be impractical. The committee should also include other stakeholders as needed, but the core should be business and IT leadership.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exclusive membership of board directors
Why it's wrong here
While board directors bring high-level oversight, they may lack the detailed IT knowledge needed to make informed decisions about IT investments and risks. An exclusive board membership could result in decisions that are disconnected from operational realities. Governance committees benefit from a mix of board members, executives, and IT leaders. The board should be involved, but not exclusively, as this would limit the committee's effectiveness in addressing both strategic and tactical IT matters.
- ✗
Majority representation by IT managers
Why it's wrong here
If IT managers dominate the committee, decisions may be skewed toward technical considerations rather than business value. This can lead to IT initiatives that are not aligned with organizational goals and may result in wasted resources. Governance committees should have diverse representation to balance technical feasibility with business needs. While IT managers provide essential expertise, they should not constitute the majority, as this could undermine the committee's ability to oversee IT from a strategic, enterprise-wide perspective.
- ✓
Inclusion of senior business executives and the CIO
Why this is correct
Effective IT governance committees require representation from both business and IT leadership to ensure that IT decisions are aligned with business strategy and that IT risks are understood across the organization. Senior business executives provide strategic direction and prioritize investments, while the CIO offers technical insight and operational feasibility. This balanced membership fosters accountability, facilitates communication, and helps the committee make informed decisions that deliver value and manage risks appropriately.
- ✗
Representation primarily from the finance department
Why it's wrong here
Finance representation is valuable for budgeting and cost control, but a committee dominated by finance may prioritize cost reduction over IT innovation and strategic value. IT governance requires a holistic view that encompasses risk, compliance, and business alignment, not just financial considerations. A balanced membership that includes business, IT, and finance is more effective. Exclusive or primary finance representation could lead to underinvestment in IT and missed opportunities for competitive advantage.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.