CISA Practice Question: Information Systems Acquisition, Development, and Implementation
During a post-implementation review of a new financial system, the IS auditor finds that user acceptance testing (UAT) was completed with only 60% of test cases passed. Which of the following is the MOST significant risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The system may not fully meet business requirements, leading to user workarounds
Low UAT pass rate indicates unresolved defects or unmet user requirements, leading to user dissatisfaction and potential workarounds that compromise controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The system deployment was delayed
Why it's wrong here
Schedule slippage is a project-management concern, not the risk arising from 40% of UAT cases failing; the real exposure is undetected defects reaching production in a financial system. It is tempting because failed testing often precedes delayed deployment, but delay is a symptom, not the control failure the auditor must report.
- ✗
The system performance is below expectations
Why it's wrong here
Performance shortfalls are one possible defect class, but the stem gives no evidence of throughput or response-time failures; the risk is that 40% of test cases failed for unknown reasons. It is tempting because UAT failures can include performance cases, yet the auditor cannot assume that specific cause from the pass rate alone.
- ✗
The project was not completed within the planned budget
Why it's wrong here
Budget overrun is a project-governance metric unrelated to the 40% of UAT cases that failed; the significant risk is defective functionality entering production. It is tempting because post-implementation reviews examine cost variance, but budget status does not indicate whether the financial system processes transactions correctly.
- ✓
The system may not fully meet business requirements, leading to user workarounds
Why this is correct
Passing only 60% of UAT cases means 40% of tested business scenarios failed, so the system may not satisfy requirements and users will adopt manual workarounds that undermine controls and reporting integrity. This is the most significant risk.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.