The IT program manager does not see the value of conducting risk assessments for a new major IT project. The manager is reluctant to cooperate with internal auditors and the newly formed steering committee.

December 11, 2021 by Admin

The IT program manager does not see the value of conducting risk assessments for a new major IT project. The manager is reluctant to cooperate with internal auditors and the newly formed steering committee. Midway through the project, program requirements were changed because the CEO is a friend of a vendor and wants to implement this vendor’s new technology. This decision will cause the current IT program budget to be insufficient and will be shown as overspending, After the requirement change request, the IT program manager should FIRST:

  • report the matter to internal audit as a program deviation to be reviewed.
  • obtain confirmation from the business and a decision by the steering committee.
  • align IT with the business and agree to the business request.
  • request additional funding from the business owner to cover the additional scope.

Leave a Reply