nerdexam
Isaca

CGEIT · Question #618

As a result of a new regulatory requirement, an enterprise's board has mandated that steps be taken to ensure related IT governance activities are performing as originally designed and are continuousl

The correct answer is A. Mandate ongoing enterprise risk and control self-assessments (CSAs). To ensure IT governance activities are performing as designed and continuously improved due to new regulatory requirements, mandating ongoing enterprise risk and control self-assessments is the best approach.

Submitted by luis.pe· Apr 18, 2026Governance of Enterprise IT

Question

As a result of a new regulatory requirement, an enterprise's board has mandated that steps be taken to ensure related IT governance activities are performing as originally designed and are continuously improved. Which of the following is the BEST approach?

Options

  • AMandate ongoing enterprise risk and control self-assessments (CSAs)
  • BConduct quarterly reviews of the enterprise business architecture
  • CEngage periodic external audit reviews of IT governance processes
  • DRequire annual mapping of key IT governance processes

How the community answered

(60 responses)
  • A
    72% (43)
  • B
    13% (8)
  • C
    5% (3)
  • D
    10% (6)

Why each option

To ensure IT governance activities are performing as designed and continuously improved due to new regulatory requirements, mandating ongoing enterprise risk and control self-assessments is the best approach.

AMandate ongoing enterprise risk and control self-assessments (CSAs)Correct

Control Self-Assessments (CSAs) involve management and staff directly evaluating the effectiveness of controls and the associated risks in their own business units. This approach fosters ownership, provides continuous feedback on control performance, identifies areas for improvement proactively, and ensures alignment with regulatory requirements, making it ideal for ongoing assurance and improvement.

BConduct quarterly reviews of the enterprise business architecture

Quarterly reviews of the enterprise business architecture focus on the structural alignment of business capabilities, not directly on the ongoing performance and improvement of IT governance *activities* and their associated controls.

CEngage periodic external audit reviews of IT governance processes

While external audits provide independent assurance, they are typically periodic snapshots, not an ongoing mechanism for continuous improvement and day-to-day performance monitoring mandated by the board.

DRequire annual mapping of key IT governance processes

Requiring annual mapping of key IT governance processes helps document processes but does not, by itself, ensure they are performing as designed or continuously improved; it's a descriptive rather than an evaluative or improvement activity.

Concept tested: IT governance control assurance and improvement

Topics

#IT governance effectiveness#Continuous improvement#Control self-assessment#IT governance monitoring

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice