Courseiva
mediumMultiple Select

Key Objectives of a Post-Implementation Review

Which TWO of the following are key objectives of a post-implementation review of a new system?

Quick Answer

The answer is verifying that the system meets user requirements and capturing lessons learned. These are the two key objectives of a post-implementation review because a PIR is fundamentally a validation and improvement exercise: it confirms that the delivered system satisfies the business needs and functional specifications defined during the requirements phase, while also documenting what worked and what did not to refine future project management and system development processes. On the CISA exam, this topic tests your understanding of the PIR’s role in the System Development Life Cycle (SDLC) and IT governance; a common trap is confusing operational acceptance testing with the PIR’s broader focus on business alignment and process improvement. To remember, think of the PIR as looking both backward (did it meet requirements?) and forward (what can we learn?), which directly supports continuous improvement. A helpful mnemonic is “R&L” for Requirements and Lessons learned.

⚠ Common exam trap

Many exam-takers confuse the PIR with project closure activities, mistakenly selecting budget variance or vendor evaluation as key objectives, when the PIR is specifically focused on verifying system effectiveness and capturing lessons learned for future projects.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify lessons learned for future projects

Option C is correct because a post-implementation review (PIR) is fundamentally a lessons-learned exercise: it captures what went well and what did not during the project so that future projects can avoid repeating mistakes and replicate successes. Option E is correct because the PIR's primary purpose is to confirm that the delivered system actually satisfies the business and user requirements defined in the original scope, often through user feedback and acceptance criteria verification. Options A, B, and D, while potentially useful activities, are not key objectives of a PIR: updating the disaster recovery plan is a separate operational/BCP task, budget variance assessment is typically part of project closure or earned value management, and vendor performance evaluation is usually handled through contract management or procurement reviews.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Update the disaster recovery plan

    Why it's wrong here

    Disaster recovery plans are updated through change management and business continuity maintenance, not as a post-implementation review objective, which evaluates whether the system met its stated business case and requirements. It tempts because new systems alter recovery dependencies, but that update is a separate continuity activity.

  • ✗

    Assess the project budget variance

    Why it's wrong here

    Budget variance is examined during project closure and cost accounting, whereas a post-implementation review assesses whether the system delivered the intended business benefits and requirements. It tempts because both occur after go-live, but variance analysis addresses project financial control, not operational effectiveness of the delivered solution.

  • ✓

    Identify lessons learned for future projects

    Why this is correct

    A post-implementation review compares actual outcomes against expectations and documents what worked and what did not, feeding that knowledge into subsequent projects. Capturing lessons learned is therefore a core objective, reducing repeated mistakes and improving future delivery.

  • ✗

    Evaluate vendor performance

    Why it's wrong here

    Vendor performance is assessed through contract management and service-level reporting, not a post-implementation review, which examines whether the delivered system meets business requirements and whether benefits were realised. It tempts because procurement reviews do evaluate suppliers, but that occurs during vendor selection or contract renewal.

  • ✓

    Verify that the system meets user requirements

    Why this is correct

    The review confirms the delivered system actually satisfies the business and user requirements it was commissioned to meet, validating that the original objectives were achieved. Verifying requirement fulfilment is thus a primary objective, distinct from ongoing operational monitoring.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. What is the PRIMARY purpose of a post-implementation review?

easy
  • A.To close the project budget and finalize costs
  • B.To evaluate the performance of the project team
  • C.To document lessons learned for future projects
  • ✓ D.To assess whether expected benefits were achieved

Why D: The primary purpose of a post-implementation review (PIR) is to determine whether the system or project has delivered the expected business benefits, such as improved efficiency, cost savings, or enhanced functionality. This aligns with the IS auditor's focus on value realization and governance, ensuring that the investment achieved its intended objectives before the project is formally closed.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.