CGEIT · Question #618
As a result of a new regulatory requirement, an enterprise's board has mandated that steps be taken to ensure related IT governance activities are performing as originally designed and are continuousl
The correct answer is A. Mandate ongoing enterprise risk and control self-assessments (CSAs). To ensure IT governance activities are performing as designed and continuously improved due to new regulatory requirements, mandating ongoing enterprise risk and control self-assessments is the best approach.
Question
As a result of a new regulatory requirement, an enterprise's board has mandated that steps be taken to ensure related IT governance activities are performing as originally designed and are continuously improved. Which of the following is the BEST approach?
Options
- AMandate ongoing enterprise risk and control self-assessments (CSAs)
- BConduct quarterly reviews of the enterprise business architecture
- CEngage periodic external audit reviews of IT governance processes
- DRequire annual mapping of key IT governance processes
How the community answered
(60 responses)- A72% (43)
- B13% (8)
- C5% (3)
- D10% (6)
Why each option
To ensure IT governance activities are performing as designed and continuously improved due to new regulatory requirements, mandating ongoing enterprise risk and control self-assessments is the best approach.
Control Self-Assessments (CSAs) involve management and staff directly evaluating the effectiveness of controls and the associated risks in their own business units. This approach fosters ownership, provides continuous feedback on control performance, identifies areas for improvement proactively, and ensures alignment with regulatory requirements, making it ideal for ongoing assurance and improvement.
Quarterly reviews of the enterprise business architecture focus on the structural alignment of business capabilities, not directly on the ongoing performance and improvement of IT governance *activities* and their associated controls.
While external audits provide independent assurance, they are typically periodic snapshots, not an ongoing mechanism for continuous improvement and day-to-day performance monitoring mandated by the board.
Requiring annual mapping of key IT governance processes helps document processes but does not, by itself, ensure they are performing as designed or continuously improved; it's a descriptive rather than an evaluative or improvement activity.
Concept tested: IT governance control assurance and improvement
Topics
Community Discussion
No community discussion yet for this question.