CISA Governance and Management of IT Practice Question
During an IT audit, the auditor discovers that the IT strategy is not formally documented. Which of the following is the MOST significant risk associated with this finding?
⚠ Common exam trap
CISA often tests the difference between a governance-level risk (strategic misalignment) and operational symptoms (cost overruns, poor performance measurement) — candidates who pick the most visible symptom instead of the root governance risk get it wrong.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Lack of alignment between IT investments and business goals.
An undocumented IT strategy means there is no formal link between technology investment decisions and business objectives, so IT spending, projects, and priorities can drift away from what the organization is actually trying to achieve. This strategic misalignment is the most significant risk because it undermines value delivery across the entire IT portfolio, not just one operational area. Auditors treat the IT strategy as the governing document that translates business goals into IT direction, so its absence is a governance-level finding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Difficulty in recruiting qualified IT staff.
Why it's wrong here
Undocumented IT strategy does not govern hiring pipelines, so recruitment difficulty is not the risk this finding creates. It tempts because a documented strategy does inform workforce planning and skills forecasting, making it the right answer when the stem asks about talent gaps rather than absent strategic direction.
- ✗
Inability to measure the performance of IT systems.
Why it's wrong here
Performance measurement depends on metrics and SLAs, which can exist without a documented strategy. The absence of a formal strategy primarily removes the basis for aligning IT direction with business goals, making measurement a secondary concern.
- ✓
Lack of alignment between IT investments and business goals.
Why this is correct
Without a documented IT strategy, investment decisions lack a formal reference point tying spend to business objectives, so resources drift toward ad hoc technical priorities rather than organisational goals. This directly satisfies the stem's alignment risk, making it the most significant consequence of the missing documentation.
- ✗
Increased operational costs due to unplanned IT initiatives.
Why it's wrong here
Undocumented strategy does not itself drive unplanned spending; cost overruns stem from absent portfolio governance, not missing documentation. Cost control is the concern where investment decisions lack business-case review or budget oversight. Here the exposure is misalignment between IT activity and business objectives, since no documented strategy exists to direct or evidence that alignment.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.