Courseiva

CISA Governance and Management of IT Practice Question

Scenario: A healthcare organization is implementing a new electronic health records (EHR) system. The project has been delayed due to scope creep and resource constraints. The project sponsor is pressuring the project manager to accelerate the timeline by skipping user acceptance testing (UAT) and going live immediately. The organization has a governance policy that requires all IT projects to complete UAT before deployment. The project manager is concerned about quality and patient safety. Which of the following is the BEST course of action?

⚠ Common exam trap

Many exam-takers choose a compromise (Option A) thinking it balances speed and quality, but it still violates the governance policy and fails to address the root cause of scope creep and resource constraints through proper escalation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adhere to the governance policy and escalate the risk to the steering committee for a decision.

The governance policy mandates UAT before deployment, and skipping it could compromise patient safety and data integrity in the EHR system. By escalating the risk to the steering committee, the project manager ensures that the decision is made at the appropriate governance level, balancing project pressures with compliance and quality. This approach aligns with the CISA domain of Governance and Management of IT, where adherence to policies and risk escalation are key controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Compromise by conducting a limited UAT on only critical functionalities.

    Why it's wrong here

    Partial UAT breaches the governance policy requiring complete acceptance testing before deployment, and untested critical interfaces can still harm patients. It is tempting because risk-based testing is legitimate when the policy itself permits scoped acceptance criteria, but here the mandate is unconditional, so the deviation needs formal approval, not unilateral compromise.

  • ✗

    Resign from the project due to ethical concerns.

    Why it's wrong here

    Resigning abandons the governance duty rather than resolving it; the project manager's role is to escalate the policy conflict through the change control or steering committee. It is tempting as a principled exit when ethics feel compromised, but resignation is warranted only after all internal escalation routes are exhausted and documented.

  • ✗

    Accept the sponsor's request and skip UAT to meet the deadline.

    Why it's wrong here

    Skipping UAT directly violates the mandatory governance policy and removes the control that detects patient-safety defects before go-live. It is tempting because schedule pressure and sponsor authority can make compliance feel optional, yet sponsor direction never overrides an established organisational policy; the correct route is escalation and a formal exception decision.

  • ✓

    Adhere to the governance policy and escalate the risk to the steering committee for a decision.

    Why this is correct

    Escalation preserves the mandatory UAT control while transferring the timeline risk decision to the steering committee, which owns governance exceptions. Skipping UAT would breach policy and expose patient safety, so the project manager must not accept that risk unilaterally.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.