nerdexam
Isaca

CGEIT · Question #40

The IT program manager does not see the value of conducting risk assessments for a new major IT project. The manager is reluctant to cooperate with internal auditors and the newly formed steering…

The correct answer is A. obtain confirmation from the business and a decision by the steering committee. After a mid-project requirement change driven by the CEO and causing budget overspending, the IT program manager should first seek formal confirmation from the business and a decision from the steering committee.

Submitted by viktor_hu· Apr 18, 2026Governance of Enterprise IT

Question

The IT program manager does not see the value of conducting risk assessments for a new major IT project. The manager is reluctant to cooperate with internal auditors and the newly formed steering committee. Midway through the project, program requirements were changed because the CEO is a friend of a vendor and wants to implement this vendor's new technology. This decision will cause the current IT program budget to be insufficient and will be shown as overspending. After the requirement change request, the IT program manager should FIRST:

Options

  • Aobtain confirmation from the business and a decision by the steering committee.
  • Brequest additional funding from the business owner to cover the additional scope.
  • Creport the matter to internal audit as a program deviation to be reviewed.
  • Dalign IT with the business and agree to the business request.

How the community answered

(24 responses)
  • A
    54% (13)
  • B
    29% (7)
  • C
    4% (1)
  • D
    13% (3)

Why each option

After a mid-project requirement change driven by the CEO and causing budget overspending, the IT program manager should first seek formal confirmation from the business and a decision from the steering committee.

Aobtain confirmation from the business and a decision by the steering committee.Correct

This action ensures that the significant change in project scope, direction, and budget is formally acknowledged and approved by the appropriate governance body, the steering committee, and business stakeholders. Formalizing the change legitimizes the new requirements and allows for proper adjustment of the project plan and budget, providing a basis for subsequent actions like requesting additional funding or reporting deviations.

Brequest additional funding from the business owner to cover the additional scope.

Requesting additional funding is premature without first formally confirming and getting the new requirements approved by the governing bodies.

Creport the matter to internal audit as a program deviation to be reviewed.

Reporting to internal audit should occur for deviations from an *approved* plan; the first step is to get the *new* plan and its deviations approved.

Dalign IT with the business and agree to the business request.

Simply agreeing to the business request does not address the governance breach or the need to formalize the budget and scope changes through proper channels.

Concept tested: Project governance and change formalization

Topics

#IT Governance#Change Management#Steering Committee#Program Management Best Practices

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice