nerdexam
Isaca

CGEIT · Question #533

An internal audit of a large financial institution found that financial data is being managed in a way that will negatively impact the enterprise's ability to support regulatory reporting. Which of th

The correct answer is A. Establish a data governance framework.. The first strategic action to address financial data management issues impacting regulatory reporting is to establish a robust data governance framework. This framework provides the overarching structure for defining roles, policies, standards, and processes necessary for managin

Submitted by marco_it· Apr 18, 2026Governance of Enterprise IT

Question

An internal audit of a large financial institution found that financial data is being managed in a way that will negatively impact the enterprise's ability to support regulatory reporting. Which of the following should be the FIRST strategic action in addressing this situation?

Options

  • AEstablish a data governance framework.
  • BAssign data responsibilities through a RACI chart.
  • CReview key risk indicators (KRIS) related to data management.
  • DUpdate data management policies.

How the community answered

(31 responses)
  • A
    81% (25)
  • B
    3% (1)
  • C
    6% (2)
  • D
    10% (3)

Why each option

The first strategic action to address financial data management issues impacting regulatory reporting is to establish a robust data governance framework. This framework provides the overarching structure for defining roles, policies, standards, and processes necessary for managing data effectively, ensuring compliance and data quality.

AEstablish a data governance framework.Correct

Establishing a data governance framework is the first strategic action because it provides the foundational structure for defining policies, roles, responsibilities, standards, and processes for managing data throughout its lifecycle. This framework ensures that financial data is managed consistently, accurately, and securely, which is critical for meeting regulatory reporting requirements and addressing the systemic issues identified by the audit.

BAssign data responsibilities through a RACI chart.

Assigning data responsibilities via a RACI chart is an important component of a data governance framework, but it presumes that the overarching framework and underlying policies for data management are already in place.

CReview key risk indicators (KRIS) related to data management.

Reviewing Key Risk Indicators (KRIs) is a monitoring activity that helps assess risk, but it doesn't establish the foundational controls and management structure needed to fix a systemic problem with data management at a strategic level.

DUpdate data management policies.

Updating data management policies is an operational step within a governance structure; without an established data governance framework, policy updates may not be effectively implemented, enforced, or aligned with broader strategic objectives.

Concept tested: Data governance framework establishment

Source: https://learn.microsoft.com/en-us/azure/architecture/data-guide/data-governance/overview

Topics

#Data Governance#Regulatory Compliance#Enterprise IT Governance#Strategic IT Management

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice