An IS auditor is reviewing the IT steering committee charter of a publicly listed Australian company. The charter lists the chief information officer as chair, the head of infrastructure as secretary, and three operational managers as voting members. No business unit head, finance representative, or non-executive director is included. Senior management argues that this composition is efficient because every member understands technology. What is the BEST response by the IS auditor?
- AConclude that the steering committee composition does not enable business-IT alignment and recommend the inclusion of business and finance representation with appropriate oversight from governance. Correct
- BAccept the composition because all voting members hold senior positions and bring deep technical knowledge that is essential for evaluating proposed investments in core platforms.
- CAccept the composition on condition that meeting minutes are circulated promptly to the executive team and that an annual report on committee decisions is presented to the audit committee.
- DRecommend that the IS audit function take a permanent voting seat on the steering committee to ensure that audit considerations directly influence each investment decision taken by the group.
Why A is correct: COBIT 2019 and ISO/IEC 38500 both expect the steering committee to balance business and IT perspectives so that investment decisions reflect enterprise direction. A committee dominated by IT cannot evidence that balance, which is a reportable governance finding.
Why B is wrong: Technical depth alone does not deliver enterprise alignment. The role of the steering committee is to ensure IT investments serve business priorities, so an all-IT membership cannot demonstrate that perspective.
Why C is wrong: Better communication of decisions does not correct an unbalanced decision-making body. The defect lies in who participates in the vote, not in how the outcomes are reported afterwards.
Why D is wrong: A voting role would compromise the IS auditor's independence, because the auditor would later be assessing decisions in which the auditor participated. ISACA standards expressly limit such direct involvement in management decisions.