CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An organization is implementing a new CRM system and has chosen a build (in-house development) approach over buying a COTS product. Which of the following is the most significant risk of this decision?
⚠ Common exam trap
CISA often tests the risks associated with build vs. buy, and candidates may incorrectly attribute COTS risks (e.g., vendor lock-in, reduced customization) to in-house development, or overlook the inherent schedule and cost risks of custom development.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Higher likelihood of project delays and budget overruns
The most significant risk of choosing an in-house build over a COTS product is the higher likelihood of project delays and budget overruns. Custom development is complex, time-consuming, and prone to scope creep, underestimation, and technical challenges. While in-house development offers customization and control, it often leads to cost and schedule overruns compared to implementing a pre-built solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Inability to customize the system to meet user requirements
Why it's wrong here
In-house development exists precisely to tailor functionality, so customisation shortfalls are not its characteristic risk. This option would fit a COTS purchase, where vendor-defined features may not match requirements and configuration is the only recourse.
- ✓
Higher likelihood of project delays and budget overruns
Why this is correct
In-house development demands the organisation define, build and test bespoke functionality itself, so scope creep and underestimated effort routinely extend timelines and budgets. COTS products carry vendor delivery risk instead, making schedule and cost overrun the most significant exposure unique to the build decision.
- ✗
Reduced control over security and data privacy
Why it's wrong here
In-house development grants the organisation full control over source code, hosting and data handling, so security and privacy control typically increases rather than diminishes. It is tempting because COTS vendors do impose their own patching cycles and data-residency terms, making reduced control a genuine risk of buying, not building.
- ✗
Vendor lock-in due to proprietary technology
Why it's wrong here
Vendor lock-in arises from dependence on a supplier's proprietary platform, which in-house development avoids by retaining source code and control. Lock-in is a genuine risk when buying COTS products, making this the wrong direction for a build decision.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.