nerdexam
Isaca

CGEIT · Question #45

The CIO of a financial services company is tasked with ensuring IT processes are in compliance with recently instituted regulatory changes. The FIRST course of action should be to:

The correct answer is D. perform a current state assessment. To ensure IT processes comply with new regulatory changes, the CIO's first action should be to perform a current state assessment.

Submitted by hassan_iq· Apr 18, 2026Governance of Enterprise IT

Question

The CIO of a financial services company is tasked with ensuring IT processes are in compliance with recently instituted regulatory changes. The FIRST course of action should be to:

Options

  • Aalign IT project portfolio with regulatory requirements.
  • Bcreate an IT balanced scorecard.
  • Cidentify the penalties for noncompliance.
  • Dperform a current state assessment.

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    13% (4)
  • D
    77% (24)

Why each option

To ensure IT processes comply with new regulatory changes, the CIO's first action should be to perform a current state assessment.

Aalign IT project portfolio with regulatory requirements.

Aligning the IT project portfolio is a subsequent step that relies on the findings of a current state assessment and gap analysis.

Bcreate an IT balanced scorecard.

Creating an IT balanced scorecard is a performance measurement tool, not the initial action for addressing new regulatory compliance.

Cidentify the penalties for noncompliance.

Identifying penalties for noncompliance is important for understanding risk, but it does not provide the actionable information needed to initiate compliance efforts; a current state assessment does.

Dperform a current state assessment.Correct

Performing a current state assessment, or a gap analysis, is the foundational first step to understand where the existing IT processes stand in relation to the new regulatory requirements. This assessment identifies which processes are already compliant, which need modification, and what new controls or procedures must be implemented, providing a clear roadmap for achieving and demonstrating compliance.

Concept tested: Regulatory compliance gap analysis

Source: https://learn.microsoft.com/en-us/compliance/regulatory/compliance-manager-assessments

Topics

#Regulatory Compliance#IT Governance#Current State Assessment#Compliance Frameworks

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice