nerdexam
Isaca

CISA · Question #407

An IS auditor discovers that an organization lacks a formal requirements validation process before software development starts. Which of the following is the PRIMARY risk associated with this deficien

The correct answer is B. Increased likelihood of scope creep, leading to project delays and cost overruns. Without a formal requirements validation process, requirements are often incomplete, ambiguous, or not agreed upon before development begins. This creates conditions for scope creep-stakeholders request additional features or changes mid-project because their actual needs were ne

Submitted by omar99· Apr 18, 2026Information Systems Acquisition, Development, and Implementation

Question

An IS auditor discovers that an organization lacks a formal requirements validation process before software development starts. Which of the following is the PRIMARY risk associated with this deficiency?

Options

  • ACompromised quality control efforts, resulting in more defects in the final product
  • BIncreased likelihood of scope creep, leading to project delays and cost overruns
  • CDifficulty of effective resource allocation by project managers, impacting availability of staff
  • DReduced communications between developers and stakeholders, resulting in slower adoption

How the community answered

(33 responses)
  • B
    91% (30)
  • C
    3% (1)
  • D
    6% (2)

Explanation

Without a formal requirements validation process, requirements are often incomplete, ambiguous, or not agreed upon before development begins. This creates conditions for scope creep-stakeholders request additional features or changes mid-project because their actual needs were never properly captured and validated upfront. Scope creep directly causes project delays and cost overruns. While quality defects (A) and communication issues (D) are real concerns, they are secondary effects. Resource allocation difficulties (C) are an indirect consequence. Scope creep is the most immediate and measurable risk of skipping requirements validation.

Topics

#Requirements Validation#Software Development Risks#Scope Creep#SDLC Controls

Community Discussion

No community discussion yet for this question.

Full CISA Practice