All Practice Exams

100+ Free ISO/IEC 38500 Lead IT Governance Manager Practice Questions

Prepare for the PECB Certified ISO/IEC 38500 Lead IT Corporate Governance Manager exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: ISO/IEC 38500 Lead IT Governance Manager Exam

12 essay, 3h

Exam Format

PECB Candidate Handbook

70%

Passing Score

PECB Candidate Handbook

USD 1000

Exam-Only Fee (Lead)

PECB Candidate Handbook

6 principles

Core Framework

ISO/IEC 38500

Open-book

Reference Materials Allowed

PECB Candidate Handbook

3 years

Credential Validity

PECB Candidate Handbook

PECB Certified ISO/IEC 38500 Lead IT Corporate Governance Manager is an open-book, 12-question, 3-hour essay exam (70% to pass, USD 1000 exam-only) covering the six IT governance principles and the Evaluate-Direct-Monitor model. The 100 MCQs here are a study adaptation for building the underlying knowledge — not a replica of the essay format.

Sample ISO/IEC 38500 Lead IT Governance Manager Practice Questions

Try these sample questions to test your ISO/IEC 38500 Lead IT Governance Manager exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1How many principles for the good corporate governance of IT does ISO/IEC 38500 establish?
A.Four principles
B.Five principles
C.Six principles
D.Eight principles
Explanation: ISO/IEC 38500 establishes six principles for good governance of IT: Responsibility, Strategy, Acquisition, Performance, Conformance, and Human Behaviour. These principles express preferred behaviour to guide the decision making of governing bodies.
2Which ISO/IEC 38500 principle requires that individuals and groups within the organization understand and accept their responsibilities in respect of both supply of, and demand for, IT?
A.Strategy
B.Conformance
C.Responsibility
D.Performance
Explanation: The Responsibility principle states that individuals and groups should understand and accept their responsibilities for both the supply of and demand for IT, and that those with responsibility for actions also have the authority to perform those actions.
3Under the Strategy principle of ISO/IEC 38500, what is the expected relationship between the organization's business strategy and its IT arrangements?
A.IT strategy should be developed independently and periodically reconciled with business strategy
B.Business strategy should be rewritten annually to follow emerging IT trends regardless of business goals
C.The organization's current and future operations should take into account IT capabilities, and plans for IT should support the business strategy
D.IT strategy is delegated entirely to the IT department without board involvement
Explanation: The Strategy principle requires that the organization's business strategy takes into account the current and future capabilities of IT, and that the strategic plans for IT satisfy the current and ongoing needs of the organization's business strategy. Alignment is bidirectional: IT both shapes and serves the business strategy.
4The Acquisition principle of ISO/IEC 38500 states that IT acquisitions should be made primarily on the basis of what?
A.The lowest available purchase price
B.The preferences of the IT department's technical staff
C.Valid reasons supported by appropriate and ongoing analysis, with clear and transparent decision making
D.The urgency of requests from individual business units
Explanation: The Acquisition principle requires that IT acquisitions be made for valid reasons, on the basis of appropriate and ongoing analysis, with clear and transparent decision making. There should be an appropriate balance between benefits, opportunities, costs, and risks over both the short and long term.
5Which ISO/IEC 38500 principle requires that IT be fit for purpose in supporting the organization and providing the services, service levels, and service quality needed to meet current and future business requirements?
A.Responsibility
B.Acquisition
C.Human Behaviour
D.Performance
Explanation: The Performance principle requires that IT be fit for purpose in supporting the organization, providing the services, levels of service, and service quality required to meet current and future business requirements. It is the principle most directly connected to monitoring actual service outcomes.
6An organization must ensure its use of IT complies with data protection legislation and that its internal IT policies are clearly defined, implemented, and enforced. Which ISO/IEC 38500 principle primarily addresses this?
A.Strategy
B.Performance
C.Human Behaviour
D.Conformance
Explanation: The Conformance principle requires that IT complies with all mandatory legislation and regulations, and that policies and practices are clearly defined, implemented, and enforced. Compliance with internal rules is treated alongside external legal obligations.
7The Human Behaviour principle of ISO/IEC 38500 requires that IT policies, practices, and decisions demonstrate what?
A.A preference for automation over human work wherever possible
B.Strict control of user actions to eliminate all human error
C.Respect for human behaviour, including the current and evolving needs of all the people in the process
D.Priority for the needs of the IT function over other staff
Explanation: The Human Behaviour principle states that IT policies, practices, and decisions should demonstrate respect for human behaviour, including the current and evolving needs of all the people in the process. It recognizes that IT succeeds or fails through people.
8How does ISO/IEC 38500 distinguish governance of IT from management of IT?
A.Governance is performed by the IT department; management is performed by the board
B.Governance and management are interchangeable terms for the same activities
C.Governance concerns the system by which the use of IT is directed and controlled by the governing body, while management executes within that direction
D.Governance applies only to outsourced IT; management applies only to internal IT
Explanation: Governance is the responsibility of the governing body and concerns evaluating, directing, and monitoring the use of IT, whereas management is concerned with executing plans and running IT activities within the direction set by the governing body. Keeping this distinction clear is central to ISO/IEC 38500.
9To whom is ISO/IEC 38500 primarily addressed?
A.IT operations staff and system administrators
B.External IT auditors and certification bodies
C.Members of governing bodies, such as owners, board members, directors, partners, and senior executives
D.Software developers and solution architects
Explanation: ISO/IEC 38500 provides guiding principles for members of governing bodies of organizations — owners, board members, directors, partners, senior executives, or similar — on the effective, efficient, and acceptable use of IT. It also informs those who advise, inform, or assist governing bodies.
10ISO/IEC 38500 describes its objective as promoting which three qualities of IT use in organizations?
A.Rapid, cheap, and automated
B.Secure, redundant, and scalable
C.Effective, efficient, and acceptable
D.Innovative, global, and compliant
Explanation: The standard's objective is to promote the effective, efficient, and acceptable use of IT in all organizations. 'Acceptable' captures the human, ethical, and societal dimensions alongside effectiveness and efficiency.

About the ISO/IEC 38500 Lead IT Governance Manager Exam

The PECB Certified ISO/IEC 38500 Lead IT Corporate Governance Manager certification validates the expertise to lead an organization in governing its use of IT using ISO/IEC 38500. It covers the six principles for good governance of IT (Responsibility, Strategy, Acquisition, Performance, Conformance, Human Behaviour) and the Evaluate-Direct-Monitor model. The official exam is an open-book, essay-type assessment; this practice bank is an English-language MCQ study adaptation that tests the same knowledge and judgment, not an official-format simulation.

Assessment

12 open-book essay questions across six competency domains, assessing comprehension, analytical skills, and applied knowledge with reasoned, evidence-supported answers

Time Limit

3 hours

Passing Score

70%

Exam Fee

USD 1000 exam-only (Lead level); included when taken with PECB partner training (PECB (Professional Evaluation and Certification Board))

ISO/IEC 38500 Lead IT Governance Manager Exam Content Outline

~17%

Principles for Good Corporate Governance of IT

Six principles as preferred behaviour for decision making: Responsibility (understood and accepted roles with matching authority), Strategy (business strategy informed by IT capability; IT plans serving business strategy), Acquisition (valid reasons, ongoing analysis, transparent decisions, short/long-term balance of benefits, opportunities, costs, risks), Performance (fit-for-purpose services and quality), Conformance (compliance with legislation; defined, implemented, enforced policies), Human Behaviour (respect for the needs of all people in the process)

~17%

Evaluate-Direct-Monitor Model of ISO/IEC 38500

Evaluate: examine and judge current and future IT use against objectives and internal/external pressures. Direct: prepare and implement plans and policies so IT use meets business objectives. Monitor: verify conformance to policies and performance against strategies through appropriate measurement systems. The three tasks form a continuous cycle

~16%

Guidance for the Corporate Governance of IT

Governance of IT as the system by which current and future IT use is directed and controlled; effective, efficient, and acceptable use; stakeholder assurance; vocabulary; guidance for advisers and service providers; governance versus management; delegation with retained accountability; applicability to organizations of all sizes and supply arrangements

~16%

Evaluate the Need and Applicability of Each Principle

Evaluating strategic alignment of each principle with organizational objectives; assessing proposals, business plans dependent on IT, internal and external pressures, opportunities and threats; weighing principles together when they conflict; evaluating internal, external, and outsourced supply arrangements while preserving governance accountability

~16%

Direct the Adherence to Each Principle

Directing through plans and policies: assigning responsibility and authority, requiring strategic alignment of IT plans, mandating transparent acquisition business cases, setting service-level expectations, enforcing conformance policies with resourced consequences, embedding human-behaviour considerations, and communicating direction effectively

~16%

Monitor All or Key Activities Related to All the Principles

Monitoring conformance to policies and performance against strategies via appropriate measurement systems; proportionate coverage of key activities; monitoring outsourced providers; benefits realization after acquisitions; people-centred indicators for Human Behaviour; reporting to the governing body and closing the loop with re-evaluation and adjusted direction

How to Pass the ISO/IEC 38500 Lead IT Governance Manager Exam

What You Need to Know

  • Passing score: 70%
  • Assessment: 12 open-book essay questions across six competency domains, assessing comprehension, analytical skills, and applied knowledge with reasoned, evidence-supported answers
  • Time limit: 3 hours
  • Exam fee: USD 1000 exam-only (Lead level); included when taken with PECB partner training

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

ISO/IEC 38500 Lead IT Governance Manager Study Tips from Top Performers

1Read ISO/IEC 38500 itself — the exam is open-book, so fast navigation of the standard's principles, definitions, and model matters more than memorization
2Learn the six principles cold: Responsibility, Strategy, Acquisition, Performance, Conformance, Human Behaviour — most exam questions trace back to them
3Practise the Evaluate-Direct-Monitor cycle as a loop: every monitoring result should feed re-evaluation and adjusted direction in your essay answers
4Train essay technique: structured arguments with reasoning and evidence, since PECB grades analytical skill and applied knowledge, not keyword recall
5Master the governance-versus-management boundary — who governs (the governing body) versus who executes (management) is a recurring exam theme
6Prepare your open-book kit in advance: tabbed hard copy of the standard, organized course notes, and a printed dictionary

Frequently Asked Questions

What is the PECB ISO/IEC 38500 Lead IT Corporate Governance Manager exam format?

The official exam comprises 12 essay-type questions with a 3-hour time limit and a 70% passing score. It is open-book: candidates may use a hard copy of the ISO/IEC 38500 standard, training course materials, personal notes, and a hard-copy dictionary. It can be taken online via the PECB Exams app or paper-based at authorised venues. Essay answers are graded on comprehension, analysis, and applied reasoning supported by evidence.

Is this practice bank the same format as the real exam?

No. The official PECB exam is essay-type, while this bank uses multiple-choice questions as an English-language study adaptation. The MCQs test the same underlying knowledge — the six principles, the Evaluate-Direct-Monitor model, and governance judgment scenarios — but they are not an official-format simulation and are not a substitute for practising structured essay answers before sitting the real assessment.

What are the six principles of ISO/IEC 38500?

Responsibility, Strategy, Acquisition, Performance, Conformance, and Human Behaviour. They express preferred behaviour to guide governing-body decision making: clear and accepted responsibilities, IT strategy aligned with business strategy, acquisitions based on valid analysis, IT that is fit for purpose, compliance with legislation and enforced policies, and respect for the needs of all people affected by IT.

What is the Evaluate-Direct-Monitor model?

It is the governance model at the heart of ISO/IEC 38500. Governing bodies Evaluate the current and future use of IT (considering objectives, pressures, opportunities, and threats), Direct the preparation and implementation of strategies and policies so IT use meets business objectives, and Monitor conformance to policies and performance against strategies through appropriate measurement systems. The three tasks operate as a continuous cycle.

How much does the exam cost and what is the passing score?

The passing score is 70%. The exam-only fee for Lead-level PECB exams is USD 1000 per the candidate handbook. Candidates who take the 5-day training course through a PECB partner have the exam (first attempt plus one free retake within 12 months), certification application, and first-year annual maintenance fee included in the course price.

What credential requirements apply after passing the exam?

Passing the exam makes you eligible to apply for a credential. The full Lead IT Corporate Governance Manager credential requires five years of professional experience (two in IT governance), 300 hours of IT governance activities, and signing the PECB Code of Ethics. Provisional (no experience) and Manager (two years, 200 hours) credentials are also available through the same exam.