Courseiva

CISA Governance and Management of IT Practice Question

Midway through a multi-year ERP implementation, the CIO asks the IS auditor to review how the organization is realizing the intended business benefits. The project is on schedule and within budget, but business unit managers report that key process changes have not been adopted. Which of the following is the MOST appropriate action for the IS auditor to recommend?

⚠ Common exam trap

The trap here is assuming that on-time, on-budget delivery equates to successful benefits realization, when the two are governed by separate mechanisms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a formal benefits realization plan with defined ownership and periodic measurement of outcome metrics.

The scenario deliberately separates delivery success from benefit realization: the project is on time and within budget, yet process changes are not adopted, meaning the investment's intended value is at risk. The governance response is to establish benefits ownership and outcome measurement through a benefits realization plan. Escalating false variances, increasing reporting cadence, or prematurely conducting a post-implementation review all fail to create accountability for outcomes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a formal benefits realization plan with defined ownership and periodic measurement of outcome metrics.

    Why this is correct

    Because the project is on time and on budget yet benefits are not materializing, the gap is in benefits management, not delivery. A formal benefits realization plan assigns accountability for outcome metrics and establishes periodic measurement so deviations trigger corrective action. This directly addresses the governance objective of ensuring IT investments deliver value, which is exactly what the CIO asked the auditor to assess.

  • ✗

    Escalate the schedule and budget variances to the audit committee for immediate action.

    Why it's wrong here

    There are no material schedule or budget variances to escalate; the project is on schedule and within budget. Escalating nonexistent variances misdirects the audit committee and consumes governance attention without addressing the real issue of unrealized benefits. The auditor's concern is value delivery, not cost or time performance, so this action fails to resolve the reported adoption problem.

  • ✗

    Perform a post-implementation review immediately to determine whether the project should be cancelled.

    Why it's wrong here

    A post-implementation review is conducted after the system has been in operation for a period sufficient to assess benefits; conducting one mid-implementation is premature and would not yield reliable evidence. Cancelling a project that is on time and within budget based on early adoption concerns is disproportionate. This action does not address the governance gap in benefits management.

  • ✗

    Recommend that the project steering committee increase the frequency of status reporting to weekly.

    Why it's wrong here

    More frequent status reporting improves visibility into tasks and milestones but does not create accountability for outcomes or measure whether the intended business benefits are achieved. The failure described is adoption of process changes, not lack of reporting cadence. Increasing reporting frequency would consume additional effort while leaving the root cause of unrealized benefits unaddressed.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.