Courseiva

CISA Governance and Management of IT Practice Question

An organization is establishing an IT governance committee. The committee's charter includes overseeing IT investments, monitoring IT performance, and ensuring compliance with regulations. Which of the following should the IS auditor recommend as the MOST important characteristic of the committee's membership?

⚠ Common exam trap

The trap here is assuming that IT governance committees should be dominated by IT or finance experts, when effective governance requires cross-functional representation to align IT with business objectives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inclusion of senior business executives and the CIO

The most important characteristic of an IT governance committee is balanced membership that includes senior business executives and the CIO. This ensures that IT decisions are aligned with business strategy, risks are managed from both business and technical perspectives, and accountability is shared. Without business representation, IT may become isolated; without IT representation, decisions may be impractical. The committee should also include other stakeholders as needed, but the core should be business and IT leadership.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Exclusive membership of board directors

    Why it's wrong here

    While board directors bring high-level oversight, they may lack the detailed IT knowledge needed to make informed decisions about IT investments and risks. An exclusive board membership could result in decisions that are disconnected from operational realities. Governance committees benefit from a mix of board members, executives, and IT leaders. The board should be involved, but not exclusively, as this would limit the committee's effectiveness in addressing both strategic and tactical IT matters.

  • ✗

    Majority representation by IT managers

    Why it's wrong here

    If IT managers dominate the committee, decisions may be skewed toward technical considerations rather than business value. This can lead to IT initiatives that are not aligned with organizational goals and may result in wasted resources. Governance committees should have diverse representation to balance technical feasibility with business needs. While IT managers provide essential expertise, they should not constitute the majority, as this could undermine the committee's ability to oversee IT from a strategic, enterprise-wide perspective.

  • ✓

    Inclusion of senior business executives and the CIO

    Why this is correct

    Effective IT governance committees require representation from both business and IT leadership to ensure that IT decisions are aligned with business strategy and that IT risks are understood across the organization. Senior business executives provide strategic direction and prioritize investments, while the CIO offers technical insight and operational feasibility. This balanced membership fosters accountability, facilitates communication, and helps the committee make informed decisions that deliver value and manage risks appropriately.

  • ✗

    Representation primarily from the finance department

    Why it's wrong here

    Finance representation is valuable for budgeting and cost control, but a committee dominated by finance may prioritize cost reduction over IT innovation and strategic value. IT governance requires a holistic view that encompasses risk, compliance, and business alignment, not just financial considerations. A balanced membership that includes business, IT, and finance is more effective. Exclusive or primary finance representation could lead to underinvestment in IT and missed opportunities for competitive advantage.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.