Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An organization is implementing a new CRM system and has chosen a build (in-house development) approach over buying a COTS product. Which of the following is the most significant risk of this decision?

⚠ Common exam trap

CISA often tests the risks associated with build vs. buy, and candidates may incorrectly attribute COTS risks (e.g., vendor lock-in, reduced customization) to in-house development, or overlook the inherent schedule and cost risks of custom development.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Higher likelihood of project delays and budget overruns

The most significant risk of choosing an in-house build over a COTS product is the higher likelihood of project delays and budget overruns. Custom development is complex, time-consuming, and prone to scope creep, underestimation, and technical challenges. While in-house development offers customization and control, it often leads to cost and schedule overruns compared to implementing a pre-built solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inability to customize the system to meet user requirements

    Why it's wrong here

    In-house development exists precisely to tailor functionality, so customisation shortfalls are not its characteristic risk. This option would fit a COTS purchase, where vendor-defined features may not match requirements and configuration is the only recourse.

  • ✓

    Higher likelihood of project delays and budget overruns

    Why this is correct

    In-house development demands the organisation define, build and test bespoke functionality itself, so scope creep and underestimated effort routinely extend timelines and budgets. COTS products carry vendor delivery risk instead, making schedule and cost overrun the most significant exposure unique to the build decision.

  • ✗

    Reduced control over security and data privacy

    Why it's wrong here

    In-house development grants the organisation full control over source code, hosting and data handling, so security and privacy control typically increases rather than diminishes. It is tempting because COTS vendors do impose their own patching cycles and data-residency terms, making reduced control a genuine risk of buying, not building.

  • ✗

    Vendor lock-in due to proprietary technology

    Why it's wrong here

    Vendor lock-in arises from dependence on a supplier's proprietary platform, which in-house development avoids by retaining source code and control. Lock-in is a genuine risk when buying COTS products, making this the wrong direction for a build decision.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.