All Practice Exams

100+ Free ISO/IEC 38500 IT Governance Manager Practice Questions

Prepare for the PECB Certified ISO/IEC 38500 IT Corporate Governance Manager exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: ISO/IEC 38500 IT Governance Manager Exam

5 essays, 50 pts

Exam Format

PECB Candidate Handbook v1.5

70%

Passing Score

PECB Candidate Handbook v1.5

USD 700

Exam-only Fee (Manager)

PECB Candidate Handbook v1.5

Open-book

Exam Type

PECB Candidate Handbook v1.5

6 principles

Core Governance Model

ISO/IEC 38500

3 years

Credential Validity

PECB Certification Maintenance Policy

PECB Certified ISO/IEC 38500 IT Corporate Governance Manager is an open-book, essay-type exam (5 essay questions, 50 points, 70% to pass) covering the six principles for good governance of IT, the Evaluate-Direct-Monitor model, roles and responsibilities, strategic alignment, and governance monitoring. Exam-only fee USD 700 (Manager level). Our 100 MCQs are a study adaptation of the essay content, not an official-format simulation.

Sample ISO/IEC 38500 IT Governance Manager Practice Questions

Try these sample questions to test your ISO/IEC 38500 IT Governance Manager exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1ISO/IEC 38500 sets out six principles for good corporate governance of IT. Which of the following is NOT one of those six principles?
A.Responsibility
B.Profitability
C.Acquisition
D.Conformance
Explanation: The six ISO/IEC 38500 principles are Responsibility, Strategy, Acquisition, Performance, Conformance, and Human Behaviour. Profitability is a business objective, not a governance principle defined by the standard.
2How does ISO/IEC 38500 define 'corporate governance of IT'?
A.The system by which the current and future use of IT is directed and controlled
B.The day-to-day management of IT operations and service delivery
C.The framework used to develop and maintain software applications
D.The process by which IT assets are procured and disposed of
Explanation: ISO/IEC 38500 defines corporate governance of IT as the system by which the current and future use of IT is directed and controlled. It deliberately mirrors the broader definition of corporate governance, which is the system by which organizations are directed and controlled.
3Which statement best captures the intent of the ISO/IEC 38500 principle of Strategy?
A.IT should pursue the most advanced technology regardless of business direction
B.Business strategy should be adjusted only after IT has selected its platforms
C.The organization's business strategy takes into account the current and future capabilities of IT, and the strategic plans for IT satisfy the current and ongoing needs of the business strategy
D.IT strategy should be delegated entirely to external service providers
Explanation: The Strategy principle is bidirectional: the business strategy must consider what IT can do now and in the future, while IT strategic plans must serve the current and ongoing needs of the business strategy. Neither side operates in isolation.
4What is the key distinction ISO/IEC 38500 draws between governance of IT and management of IT?
A.Governance is performed only by external auditors while management is internal
B.Governance applies only to large enterprises while management applies to small organizations
C.Governance and management are interchangeable terms for the same activities
D.Governance is the directing and controlling role exercised by the governing body, while management executes plans within that direction
Explanation: ISO/IEC 38500 assigns governance to the governing body (such as the board), which evaluates, directs, and monitors the use of IT. Management is responsible for planning, building, running, and reporting within the direction set by the governing body.
5The Human Behaviour principle of ISO/IEC 38500 requires that IT policies, practices, and decisions:
A.Eliminate human involvement from critical IT processes
B.Demonstrate respect for human behaviour, including the current and evolving needs of all the people in the process
C.Prioritize automation targets over workforce considerations
D.Apply only to the IT department's staff
Explanation: The Human Behaviour principle requires that IT policies, practices, and decisions show respect for human behaviour, including the current and evolving needs of all the 'people in the process'. This recognizes that IT outcomes depend on how people adopt and use technology.
6Under the Conformance principle of ISO/IEC 38500, what must an organization ensure about its use of IT?
A.IT complies with all mandatory legislation and regulations, and policies and practices are clearly defined, implemented, and enforced
B.IT compliance is reviewed only when a regulator requests it
C.Only contractual obligations need to be considered, since legislation is a legal department matter
D.Compliance can be assumed once policies have been published on the intranet
Explanation: The Conformance principle requires that IT complies with all mandatory legislation and regulations, and that policies and practices are clearly defined, implemented, and enforced. Publishing a policy is not enough; enforcement and demonstrated compliance are required.
7Which of the following best describes decision making required by the ISO/IEC 38500 Acquisition principle?
A.Acquisitions should be approved quickly to avoid delaying projects
B.Decisions should follow the recommendation of the preferred vendor
C.Acquisitions should be made for valid reasons, on the basis of appropriate and ongoing analysis, with clear and transparent decision making
D.Acquisition decisions should be delegated to the IT procurement officer without board visibility
Explanation: The Acquisition principle requires valid reasons, appropriate and ongoing analysis, and clear, transparent decision making. It also requires an appropriate balance between benefits, opportunities, costs, and risks in both the short and the long term.
8The Performance principle of ISO/IEC 38500 focuses on ensuring that IT:
A.Achieves the highest benchmark scores in its industry
B.Minimizes cost above all other considerations
C.Operates with the newest available hardware and software
D.Is fit for purpose in supporting the organization, providing the services, service levels, and service quality required to meet current and future business requirements
Explanation: The Performance principle is about fitness for purpose: IT must provide the services, levels of service, and service quality the organization needs now and in the future. Benchmarks, cost minimization, and technology novelty are not the criteria the principle sets.
9According to the Responsibility principle of ISO/IEC 38500, individuals and groups must understand and accept their responsibilities in respect of:
A.The supply of IT only, since demand is a business matter
B.Both the supply of, and the demand for, IT
C.Only the technical delivery of IT services
D.The governance of third-party contracts exclusively
Explanation: The Responsibility principle explicitly covers both the supply of IT and the demand for IT. It also requires that those who are assigned responsibility for actions have the authority to perform those actions.
10Which statement about the history and status of ISO/IEC 38500 is correct?
A.It was originally developed by the European Union as a regulation for financial institutions
B.It is a certifiable management system standard with mandatory clauses like ISO/IEC 27001
C.It was derived from the Australian Standard AS 8015 and provides principles-based guidance rather than certifiable requirements
D.It applies only to organizations headquartered in ISO member countries
Explanation: ISO/IEC 38500 originated from the Australian Standard AS 8015 for corporate governance of IT. It is a guidance standard expressing principles and a model for governing bodies; it does not contain certifiable requirements in the way management system standards do.

About the ISO/IEC 38500 IT Governance Manager Exam

The PECB Certified ISO/IEC 38500 IT Corporate Governance Manager certification validates the ability to apply the ISO/IEC 38500 principles and the Evaluate-Direct-Monitor model to the corporate governance of IT. The official exam is an open-book essay assessment (5 essay questions, 50 points, passing score 70%) covering the six governance principles, the EDM model, roles and responsibilities, strategic alignment, and monitoring of IT governance. This practice bank is an English-language MCQ study adaptation that tests the same underlying knowledge; it is not an official-format simulation and is no substitute for essay-writing practice.

Assessment

Five essay questions mapped to the competency domains (each 20% of the exam): three questions measuring comprehension, application, and analysis, and two measuring synthesis and evaluation. Open-book; answers must justify and explain concepts.

Time Limit

Not stated in the PECB candidate handbook for this exam

Passing Score

70%

Exam Fee

USD 700 exam-only (Manager level); included when taken with PECB partner training (PECB (Professional Evaluation and Certification Board))

ISO/IEC 38500 IT Governance Manager Exam Content Outline

20%

Principles for good Corporate Governance of IT

Understanding, interpreting and illustrating IT governance concepts: operations of ISO and development of governance principles, IT frameworks and their sources (laws, regulations, standards, contracts, market practices, internal policies), and relationships between IT standards.

20%

Evaluate-Direct-Monitor Model of ISO/IEC 38500

Evaluating current and future use of IT including internal and external supply arrangements, directing the preparation and implementation of plans and policies so IT use meets business objectives, and monitoring conformance of policies and performance of IT via measurement systems.

20%

Guidance for the Corporate Governance of IT

Applying the guidance sub-clauses for the general principles, assigning roles and responsibilities for current and future use of IT, identifying governance mechanisms and ensuring their appropriateness, and establishing the GEIT project team and project plan.

20%

Evaluate the need and applicability of each principle

Evaluating strategic alignment of the principles with business and IT strategy and structures, the Strategic Alignment Model and its alignment domain relationships, strategy formulation steps, alignment barriers, and portfolio management goals and activities.

10%

Direct the adherence to each principle

Directing adherence to the six principles: responsibilities for supply and demand of IT, current and future IT capabilities, transparent acquisition decision making, performance measurement, conformance obligations, and respect for human behaviour.

10%

Monitor all or key activities related to all the principles

Monitoring the extent to which IT satisfies obligations, internal conformance to the governance system, compliance reporting and audit practices, disposal of assets and data, continuity and risk evaluation plans, COBIT goal metrics, and risk assessment methods.

How to Pass the ISO/IEC 38500 IT Governance Manager Exam

What You Need to Know

  • Passing score: 70%
  • Assessment: Five essay questions mapped to the competency domains (each 20% of the exam): three questions measuring comprehension, application, and analysis, and two measuring synthesis and evaluation. Open-book; answers must justify and explain concepts.
  • Time limit: Not stated in the PECB candidate handbook for this exam
  • Exam fee: USD 700 exam-only (Manager level); included when taken with PECB partner training

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

ISO/IEC 38500 IT Governance Manager Study Tips from Top Performers

1Memorise the six principles and their exact intent — Responsibility, Strategy, Acquisition, Performance, Conformance, Human Behaviour — and practise matching scenario descriptions to each principle
2Master the Evaluate-Direct-Monitor cycle: know which task involves judgment on current and future use, which sets plans and policies, and which checks conformance and performance
3The exam is open-book and essay-based: practise writing structured answers that justify and explain, and tab your copy of the standard for fast navigation
4Learn the Strategic Alignment Model's four domains (business strategy, IT strategy, organizational infrastructure and processes, IS infrastructure and processes) and the four alignment perspectives
5Remember that governance accountability stays with the governing body even when IT is outsourced — supply arrangements internal or external must still be evaluated and monitored
6Know the monitoring toolkit: reporting and audit practices, COBIT goal metrics (enterprise, process, IT-related), risk assessment methods, and disposal of assets and data

Frequently Asked Questions

What is the format of the PECB ISO/IEC 38500 IT Corporate Governance Manager exam?

The official exam consists of 5 essay-type questions worth 10 points each (50 points total). It is open-book: candidates may use a copy of the ISO/IEC 38500 standard, training course materials, and personal notes. The passing score is 70%. Because it is essay-based, candidates must justify and explain concepts rather than simply recall them.

Is this practice bank the same format as the real exam?

No. The official PECB exam is an open-book essay assessment, not multiple-choice. This bank is an English-language MCQ study adaptation that tests the same knowledge domains — the six principles, the Evaluate-Direct-Monitor model, roles and responsibilities, strategic alignment, and monitoring — but it is not an official-format simulation and cannot substitute for essay-writing practice with the standard.

What are the six principles of ISO/IEC 38500?

The six principles for good corporate governance of IT are: Responsibility (understand and accept responsibilities for supply of and demand for IT), Strategy (business strategy considers IT capabilities and IT plans serve business needs), Acquisition (valid, analysed, transparent purchasing decisions), Performance (IT is fit for purpose), Conformance (compliance with all mandatory obligations), and Human Behaviour (respect for the people in the process).

How much does the exam cost and what credential can I get?

The exam-only fee is USD 700 at the Manager level; it is included in the price when you train with a PECB partner. After passing, you can apply for the Provisional IT Governance Manager credential (no experience required) or the full IT Corporate Governance Manager credential, which requires two years of professional experience (one in IT governance) plus 200 hours of IT governance activities.

What is the Evaluate-Direct-Monitor model?

It is the governance model at the heart of ISO/IEC 38500. The governing body Evaluates the current and future use of IT (strategies, proposals, supply arrangements), Directs by preparing and implementing plans and policies so IT use meets business objectives, and Monitors conformance to policies and performance against plans through measurement systems. The three tasks form a continual cycle.

How should I prepare for an open-book essay exam?

Learn to navigate the ISO/IEC 38500 standard and your course materials quickly, because the exam rewards justified, well-structured answers rather than recall. Practice writing short essays that apply the six principles and the EDM model to scenarios, and prepare tabbed, annotated hard copies of permitted reference materials.