StudyToCert

All certifications / CISA / Lessons

ISACA Certified Information Systems Auditor (CISA) 2024 job practice · Domain 3: Information systems acquisition, development and implementation

Project governance and management: roles, steering, earned value and project risk

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Many IT failures are project failures: systems delivered late, over budget, missing key controls or not delivering the benefits promised in the business case. Project governance makes sure projects are justified, directed and monitored by the right people, and project management delivers them. The IS auditor checks that both work, often during the project rather than after, when problems are still cheap to fix. Key roles include the project sponsor, a senior business leader who owns the business case, provides funding and direction and is accountable for realizing benefits; the project steering committee, which makes major decisions and approves changes to scope, budget or schedule beyond the project manager's authority; the project manager, who plans and runs day-to-day work and reports status; the project management office (PMO), which sets methods and standards and tracks the portfolio of projects; and users and system owners, who define requirements and accept the result. Quality assurance, security and risk staff advise on standards and controls. An IS auditor may participate to advise on controls, but must not take a decision-making role that would compromise independence later.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISA for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISA study plan