nerdexam
Isaca

CGEIT · Question #254

A regulatory audit assessed an enterprise's main transactional application as noncompliant. In addition to fines and required corrections, an agreement was reached to implement a set of governance con

The correct answer is D. The board of directors. Ultimate accountability for establishing and overseeing IT governance controls, particularly after a regulatory non-compliance, is best assigned to the board of directors.

Submitted by tarun92· Apr 18, 2026Governance of Enterprise IT

Question

A regulatory audit assessed an enterprise's main transactional application as noncompliant. In addition to fines and required corrections, an agreement was reached to implement a set of governance controls over IT. Accountability for these controls is BEST assigned to which of the following?

Options

  • ACIO
  • BInternal audit director
  • CApplication users
  • DThe board of directors

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    10% (3)
  • C
    3% (1)
  • D
    81% (25)

Why each option

Ultimate accountability for establishing and overseeing IT governance controls, particularly after a regulatory non-compliance, is best assigned to the board of directors.

ACIO

While the CIO is responsible for implementing and managing IT, ultimate accountability for overall IT governance and regulatory compliance rests with the board, not solely with IT management.

BInternal audit director

The internal audit director assesses controls but is not accountable for establishing or managing the controls themselves; their role is independent assurance.

CApplication users

Application users are responsible for following procedures and controls, but they do not hold accountability for the design or strategic oversight of IT governance controls.

DThe board of directorsCorrect

The board of directors holds the ultimate oversight and fiduciary responsibility for the entire enterprise, including ensuring compliance with regulations and establishing effective IT governance. After a regulatory non-compliance finding, assigning accountability to the board reinforces the critical importance of these controls at the highest level.

Concept tested: Ultimate accountability for IT governance

Source: https://www.isaca.org/resources/isaca-journal/issues/2012/volume-2/how-boards-of-directors-can-improve-it-governance

Topics

#IT Governance#Accountability#Regulatory Compliance#Board Oversight

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice