The board of directors' primary IT governance responsibility is to:
Opening subject page...
Loading your content
CPA Isc Quiz
Practice Evaluate It Governance Structures And Responsibilities in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
Question 1 / 20
0 of 20 answered
The board of directors' primary IT governance responsibility is to:
This quiz focuses on Evaluate It Governance Structures And Responsibilities, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
The board of directors' primary IT governance responsibility is to:
Explanation: The board's IT governance role is strategic oversight - ensuring IT is directed toward organizational goals and that IT-related risks are understood and managed at the enterprise level. Answer A is correct. Individual project approvals (B) are management decisions. Daily operations (C) and policy development (D) are management responsibilities.
Which of the following organizational structures best supports strong IT governance?
Explanation: A cross-functional IT steering committee brings business context to technology decisions, ensuring alignment between IT priorities and business needs - the hallmark of effective IT governance. Answer D is correct. IT-only decision-making (A, B) lacks business alignment. Internal audit provides assurance, not governance (C).
Which of the following IT governance responsibilities belongs to the audit committee of the board?
Explanation: The audit committee's IT governance role focuses on financial reporting integrity, internal controls, and audit findings - including IT risks and controls relevant to financial reporting. Answer A is correct. Capital budget approval (B) is an executive or full board function. Vendor management (C) and security policy development (D) are management activities.
An organization's IT governance framework lacks a formal IT investment prioritization process. The most likely consequence is:
Explanation: Without a prioritization process, IT resources may be allocated to lower-value projects while high-priority strategic initiatives go unfunded - misaligning IT with business needs. Answer C is correct. Budget sufficiency (A) and regulatory fines (B) are not direct consequences. Missing prioritization processes are not automatically material weaknesses (D).
An organization implements key performance indicators (KPIs) to measure IT governance effectiveness. Which of the following KPIs would be most directly relevant?
Explanation: IT governance KPIs measure strategic alignment, risk management, and control effectiveness - the core objectives of governance. Answer A is correct. Staff certifications (B), headcount benchmarks (C), and helpdesk speed (D) are operational metrics that do not directly measure governance effectiveness.
A company's board of directors receives no formal IT reporting. Senior management handles all IT decisions without board visibility. This governance gap most significantly risks:
Explanation: Without board-level IT visibility, significant risks (cyberattacks, technology failures, strategic misalignment) may not receive the governance attention they require - a fundamental oversight gap. Answer C is correct. Software approvals (A) and performance reviews (B) are management matters. Vendor pricing (D) is a procurement issue.
An organization's IT governance maturity is assessed using a model similar to CMMI. The organization is found to be at a 'repeatable' level. This means:
Explanation: The 'Repeatable' level (Level 2 in CMMI-based models) indicates processes are established and followed consistently but may lack the formal documentation and standardization of higher maturity levels. Answer B is correct. Optimized (A) is Level 5. Fully defined and measured (C) is Level 3-4. Ad hoc (D) is Level 1.
Which of the following represents a key characteristic of a well-functioning IT steering committee?
Explanation: An effective IT steering committee is cross-functional (business + IT), operates regularly, and makes substantive decisions about IT investments and priorities aligned to business strategy. Answer A is correct. IT-only decision-making (B) lacks alignment. A reporting-only body (C) is not a governance committee. External-only composition (D) lacks organizational context.
Which of the following IT governance activities most directly supports the board's oversight of cybersecurity risk?
Explanation: Board oversight of cybersecurity requires regular, meaningful reporting on risk posture, incidents, and improvement - enabling the board to fulfill its governance responsibility. Answer B is correct. Penetration testing (A), SOC implementation (C), and staff training (D) are management/operational activities that support security but are not board governance activities.
An auditor evaluating an organization's IT governance finds that IT-related risks are managed within the IT department but are not included in the enterprise risk management (ERM) framework. The primary concern is:
Explanation: Siloed IT risk management prevents the organization from understanding how IT risks interact with operational, financial, and strategic risks - a critical gap in enterprise governance. Answer A is correct. IT authority (B) is not the issue. Regulatory requirements (C) vary. Internal audit independence (D) is unrelated.
Which of the following represents the most significant indicator of weak IT governance?
Explanation: The combination of unstrategic IT investments and unaccountable IT failures are the hallmarks of weak governance - investments are not aligned, and failures are not escalated or addressed at the appropriate level. Answer C is correct. Infrastructure mix (A), occasional overruns (B), and CIO tenure (D) are operational matters, not governance indicators.
A company implements a formal IT governance framework based on COBIT. Which of the following outcomes would best demonstrate that the framework is operating effectively?
Explanation: Framework effectiveness is demonstrated by outcomes: strategic alignment, active risk management, and measurable governance improvement - not just adoption or training. Answer D is correct. Framework adoption (A) and training (B) are inputs. Budget reduction (C) is a potential benefit but not a governance effectiveness indicator.
Which of the following IT governance documents is most useful for clarifying how IT decisions are made and who has authority for different types of IT decisions?
Explanation: An IT RACI or decision rights framework explicitly defines who makes, approves, and is consulted on different IT decisions - a foundational governance document that clarifies accountability and authority. Answer B is correct. The DR plan (A), asset inventory (C), and performance reviews (D) serve operational purposes, not governance decision clarity.
An organization's IT governance framework assigns accountability for IT risk to the CIO. Which of the following best describes how this accountability should operate in practice?
Explanation: CIO accountability for IT risk means actively managing and escalating risks - not resolving them in isolation or delegating accountability away. The CIO coordinates but involves executive and board stakeholders for material risks. Answer D is correct. Sole CIO resolution (A) misses governance input. Risk scope should be comprehensive (B). Accountability cannot be fully delegated (C).
Which of the following correctly describes the purpose of an IT charter or IT governance policy?
Explanation: An IT governance charter or policy defines the governance framework - who is responsible for what, how decisions are made, and how accountability is maintained - establishing the rules of engagement for IT governance. Answer D is correct. Technical specifications (A), budget plans (B), and DR procedures (C) are operational documents, not governance charters.
A company's annual external audit includes an evaluation of IT governance. The external auditor finds that the audit committee receives detailed IT audit reports but never asks questions or requires follow-up on significant findings. This observation indicates:
Explanation: Effective governance requires active engagement - asking questions, demanding explanations, and following up on remediation. Passive report receipt without engagement is a governance failure. Answer D is correct. Delegation (A) requires formal action. Technical complexity (B) may be a contributing factor but is not the finding. External auditors cannot substitute for the audit committee (C).
Which of the following best describes the role of internal audit in IT governance?
Explanation: Internal audit's IT governance role is assurance - independently evaluating whether governance processes, risk management, and controls are effective and reporting to the audit committee. Answer B is correct. Implementing controls (A) would impair independence. Investment prioritization (C) is a steering committee function. Strategy development (D) is management's role.
Under Sarbanes-Oxley (SOX), management and the board have specific IT governance obligations related to:
Explanation: SOX requires management and the board to maintain and assess the effectiveness of internal controls over financial reporting - which includes ITGCs over financial systems. Answer C is correct. Staff certifications (A) and maturity frameworks (B) are not SOX requirements. IT incidents are not required to be disclosed in proxy statements (D).
In evaluating IT governance structures, an auditor finds that the organization has no documented IT governance framework but has a very experienced and capable CIO who manages IT effectively. How should the auditor assess this situation?
Explanation: Governance that relies on individual capability rather than documented structures and processes is fragile - it creates key person dependency risk. If the CIO leaves or is unavailable, there is no institutional framework to maintain governance. Answer C is correct. Individual competence is not a governance structure (A). CIO replacement (B) is not the solution. Organization size does not eliminate governance risk (D).
Which of the following best describes the primary purpose of IT governance?
Explanation: IT governance establishes the leadership structures, processes, and accountability mechanisms that ensure IT investments and activities align with and support organizational strategy and objectives. Answer B is correct. Day-to-day operations (A), staff training (C), and procurement (D) are management activities, not governance.