CISA Governance and Management of IT Practice Question
Which THREE of the following are indicators of mature IT governance?
⚠ Common exam trap
CISA often tests the confusion between operational metrics (like project timeliness or staff retention) and true governance indicators (like risk management and strategic alignment).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IT risks are formally assessed and managed.
Option B is correct because mature IT governance requires a formal, repeatable risk management process — risks are identified, assessed, prioritized, and mitigated with defined ownership and reporting, typically aligned to frameworks such as COBIT or ISO/IEC 27005. Option D is correct because governance maturity means IT strategy and investment decisions are driven by and traceable to business objectives, not by technology for its own sake. Option E is correct because board-level oversight through regular IT performance reporting (KPIs, dashboards, risk and compliance updates) demonstrates accountability and direction-setting at the highest level of the organization. Option A does not belong because high staff retention is an HR outcome that may reflect pay or market conditions rather than governance maturity. Option C does not belong because on-time, on-budget delivery is a project management performance metric, not an indicator of governance maturity — projects can be delivered efficiently under poor governance and vice versa.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IT department has high staff retention.
Why it's wrong here
High staff retention reflects HR and workplace conditions rather than governance structures, decision rights or accountability. It is tempting because stable teams support continuity, and would be correct as an indicator of organisational culture or workforce management maturity.
- ✓
IT risks are formally assessed and managed.
Why this is correct
Formal assessment and management of IT risks indicates mature IT governance by demonstrating a structured, proactive approach to safeguarding organisational assets. This systematic process moves beyond ad-hoc reactions, encompassing continuous identification, evaluation, mitigation, and monitoring of potential threats. Such formalisation signifies an organisation's commitment to repeatable, controlled mechanisms for achieving strategic objectives, a definitive characteristic of governance maturity.
- ✗
IT projects are completed on time and within budget.
Why it's wrong here
On-time, on-budget delivery measures project management performance, not governance maturity, which concerns value delivery, risk oversight and resource optimisation. It is tempting because delivery metrics are commonly reported to boards, and would be correct when assessing portfolio or programme execution capability.
- ✓
IT decisions are aligned with business strategy.
Why this is correct
Aligning IT decisions with business strategy shows governance directs technology investment toward organisational objectives rather than isolated technical goals. This integration of IT and business planning demonstrates mature oversight, ensuring IT delivers value and supports strategic outcomes.
- ✓
The board receives regular IT performance reports.
Why this is correct
Regular IT performance reporting to the board demonstrates oversight and accountability at the highest level of governance. It evidences that IT is monitored against agreed objectives, providing directors with the information needed to challenge and steer IT investment, which is a hallmark of mature governance.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.