CISA Question of the Day: IT Risk Appetite

CISA exam practice question — CISA Question of the Day: IT Risk Appetite

CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Governance and Management of IT.

Question

During an engagement the auditor finds that IT decisions are made variably across divisions and there is no documented risk appetite. The board asks for a governance improvement that will align IT decisions with organizational strategy and acceptable risk levels. Which action should the auditor recommend?

  • A. Deploy an automated vulnerability and configuration scanning program across production systems to detect technical weaknesses
  • B. Require an annual update of IT policies and procedures without changing governance structures or reporting lines
  • C. Develop and approve a formal, board‑endorsed IT risk appetite and tolerance statement that is cascaded into IT policies, budgets and decision criteria
  • D. Create a separate IT risk committee reporting to the CIO to centralize risk decisions within IT
Show the answer and explanation

Correct answer: C. Develop and approve a formal, board‑endorsed IT risk appetite and tolerance statement that is cascaded into IT policies, budgets and decision criteria

The best recommendation is to develop a board‑endorsed IT risk appetite and tolerance statement and embed it into policies, budgets and decision criteria. A documented risk appetite provides clear governance direction and aligns IT decisions with organizational strategy and acceptable risk levels. Option 1 (automated scanning) improves technical controls and detection but does not provide governance guidance or align decisions at the board level. Option 2 (annual policy updates without governance change) may keep documents current but fails to create the executive mandate or escalation needed for consistent decision-making. Option 4 (committee reporting to the CIO) concentrates authority within management and lacks independent board endorsement, weakening enterprise governance.

Want more practice?

Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.