IT Governance and the Board's Role
Governance sets direction and holds management to account; management runs IT within it. Confusing the two is the fastest way to answer a Domain 2 question wrong.
What this makes you able to do
Evaluate whether an organisation's IT governance framework holds management accountable to the board for the use of IT.
By the end you can
- Distinguish governance from management and say which body owns each.
- Identify the board's non-delegable responsibilities for IT.
- Recognise when a reporting line or committee structure undermines governance.
Transcript
I-T governance and the board’s role. This lesson is about the distinction the whole of Domain 2 rests on: the difference between governing I-T and managing it, and what belongs to the board that can never be handed down.
Picture a company that directs its I-T well. There is a steering committee, a strategy document, and a C-I-O who clearly runs a tight operation. Everything looks healthy. Then you notice two things. The steering committee reports to the C-I-O, and the board has not discussed I-T in over a year. Nothing is technically broken, and yet the governance is.
Here is the distinction. Governance sets direction and holds people accountable for following it. Management runs I-T within that direction. Governance asks what I-T should achieve for the enterprise and whether management is delivering it. Management asks how to deliver it with the resources available. Most Domain 2 questions turn on this line.
So keep the two jobs separate in your head. Governance is the board’s work: what should I-T achieve, what risk are we willing to carry, and is management actually delivering. Management is the C-I-O’s work: how do we deliver what governance asked for, and with what resources. When an option has the board designing controls or picking technologies, it is wrong, that is management. When an option has management setting the enterprise’s risk appetite, that is wrong too, that belongs to governance.
Now the line that cannot move. A board can delegate authority to a committee. What it cannot delegate is accountability. It remains answerable to shareholders and regulators for the value I-T delivers and the risk it carries, no matter how much decision-making it hands down.
So what stays with the board, non-delegable. First, setting the strategic direction for I-T, so that I-T supports the enterprise’s objectives rather than its own.
Second, ensuring I-T actually delivers value for what it costs. And third, ensuring I-T risk is managed within an appetite the board itself has defined. Value and risk, both owned at the top.
And fourth, holding management accountable, through reporting the board can actually rely on. Set direction, ensure value, ensure risk is managed, hold management to account. Those four do not move down the organisation.
The fastest way to spot broken governance is to follow the reporting line, exactly as you would for the audit function in Domain 1. Oversight cannot report to the thing it oversees.
Which is the real failure in our scenario. A steering committee exists to align I-T with business needs on behalf of the enterprise. If it is chaired by the C-I-O and reports to the C-I-O, it oversees I-T while answering to the head of I-T. It cannot give independent, business-driven direction. The structure has quietly turned oversight into self-endorsement.
And here is the trap that costs marks. The instinct is to judge governance by how well I-T is run. But a superbly managed I-T function with no board oversight is still a governance failure, because good management is not a substitute for accountability. The exam rewards keeping the two apart.
So carry this question into every Domain 2 scenario. Do not ask, is I-T working well. Ask, who set the direction, and who holds them to it. That is the difference between management and governance, and it is what the exam is testing.
1.Which of the following is the PRIMARY responsibility of the board of directors with respect to IT governance?
2.An IS auditor finds that the IT steering committee is chaired by the CIO and reports only to the CIO. What is the auditor's GREATEST concern?
3.The board delegates authority for IT decisions to an IT strategy committee. Which of the following does the board retain regardless of that delegation?
Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.
Stay ahead of cyber threats
Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.
No spam. Unsubscribe at any time.
