CGEIT · Question #254
A regulatory audit assessed an enterprise's main transactional application as noncompliant. In addition to fines and required corrections, an agreement was reached to implement a set of governance con
The correct answer is D. The board of directors. Ultimate accountability for establishing and overseeing IT governance controls, particularly after a regulatory non-compliance, is best assigned to the board of directors.
Question
A regulatory audit assessed an enterprise's main transactional application as noncompliant. In addition to fines and required corrections, an agreement was reached to implement a set of governance controls over IT. Accountability for these controls is BEST assigned to which of the following?
Options
- ACIO
- BInternal audit director
- CApplication users
- DThe board of directors
How the community answered
(31 responses)- A6% (2)
- B10% (3)
- C3% (1)
- D81% (25)
Why each option
Ultimate accountability for establishing and overseeing IT governance controls, particularly after a regulatory non-compliance, is best assigned to the board of directors.
While the CIO is responsible for implementing and managing IT, ultimate accountability for overall IT governance and regulatory compliance rests with the board, not solely with IT management.
The internal audit director assesses controls but is not accountable for establishing or managing the controls themselves; their role is independent assurance.
Application users are responsible for following procedures and controls, but they do not hold accountability for the design or strategic oversight of IT governance controls.
The board of directors holds the ultimate oversight and fiduciary responsibility for the entire enterprise, including ensuring compliance with regulations and establishing effective IT governance. After a regulatory non-compliance finding, assigning accountability to the board reinforces the critical importance of these controls at the highest level.
Concept tested: Ultimate accountability for IT governance
Source: https://www.isaca.org/resources/isaca-journal/issues/2012/volume-2/how-boards-of-directors-can-improve-it-governance
Topics
Community Discussion
No community discussion yet for this question.