What's changed: Initial version
6.4System audit and governance
Covers project audit (independent evaluation and corrective recommendations) that assesses a project's management status from an independent standpoint, PMO (Project Management Office), which standardizes, supports, and controls projects across an organization, and IT governance, which steers IT investment direction for the organization as a whole—together, the perspective of running a project properly under organizational control.
A project team's own self-assessment that "things are going well" is not necessarily objective. Organizations offset the blind spots and biases of individual PMs' judgment by having an audit mechanism that inspects management status from a position independent of the project team, and a PMO that maintains standards across multiple projects. A PM is expected to treat audits and the PMO not as "a nuisance that watches over you" but as a mechanism that safeguards the project's health.
6.4.1Project audit and corrective recommendations
- Project audit is the activity where an auditor independent of the project team inspects the project's planning, execution, and control status, evaluating compliance with regulations/standards and the adequacy of risk management. Unlike self-review by the PM or team itself, its value lies in evaluating objectively from the viewpoint of a disinterested third party.
- Audit results are compiled as corrective recommendations, and for each finding (e.g., incomplete change-management records, a stalled risk register), an improvement plan with a clear owner and deadline is required. An audit is not a one-off event; it only becomes effective when it includes a follow-up on whether the corrective actions were actually implemented and are working.
6.4.2PMO and IT governance
- PMO (Project Management Office) is a cross-organizational function that spans multiple projects within an organization, handling maintenance of project-management standards (templates, methods), support for individual PMs (know-how, training), and control through organization-wide visibility into progress and risk. How deeply a PMO is involved ranges, by organization, from "standards-only (supportive)" to "directly controlling projects (controlling)."
- IT governance is the mechanism that governs, from a management-level viewpoint, whether IT investment aligns with business strategy and whether risk is properly managed. It sits at a higher vantage point than project-level management, judging not just the success or failure of individual projects but whether the portfolio of multiple projects as a whole serves the organization's objectives. Project audits and PMO activity are positioned as concrete means of realizing this IT governance.
Most-tested contrasts: "project audit = objective evaluation by an independent third party, effective only when it includes follow-up on corrective recommendations", "PMO = spans standards/support/control across the organization, with the degree of involvement varying by organization", and "IT governance = governs portfolio-wide alignment from a management viewpoint, with audits/PMO as its means." Questions probe the perspective of treating an audit not as nitpicking but as a mechanism that drives improvement.
Suppose a PMO staff member receives corrective recommendations from an independent auditor regarding one of several in-house projects. The finding was that "the risk register has not been updated even once in the last three months, and many of the originally identified risks have gone stale and been left unaddressed." Asking the project's PM for an explanation yields: "the schedule was tight, and there was no time left to update the risk register." The first thing the PMO should do is treat this finding not as a personal reprimand but as an opportunity to check, across the organization, whether a similar problem is occurring elsewhere. Concretely, the PMO asks the PM to submit an improvement plan with a clear owner and deadline (e.g., bring the risk register up to date within two weeks and resume biweekly reviews going forward), and commits to a follow-up report to the auditor. At the same time, the PMO checks the risk-register update status across other ongoing projects as well, to see whether similar stalling stems from a structural problem (e.g., an unwieldy risk-management template, or a review meeting that has become a formality). If similar stalling shows up in multiple projects, the PMO goes beyond cautioning individual PMs and takes action on both the supportive and controlling fronts—revisiting the risk-management process standard itself and rolling out a more workable template and review structure organization-wide. Furthermore, because an accumulation of such management shortfalls in individual projects can undermine the overall IT-investment payoff management expects (what IT governance asks: "does the portfolio as a whole serve the organization's objectives"), the PMO also feeds the trend in audit results into regular reporting to management. In this way, taking an audit's corrective recommendations beyond a one-off fix and connecting them to organizational standard improvement and input for governance is the practice of the PMO and of audit.
| Perspective | Actor | Main role |
|---|---|---|
| Project audit | Independent auditor | Objective evaluation, corrective recommendations, follow-up |
| PMO | Cross-organizational PM support function | Standards, PM support, control of progress/risk |
| IT governance | Management | Strategic alignment of IT investment and the portfolio as a whole |
Trap: "An audit's corrective recommendation is complete once the cited PM personally responds" is wrong—an audit is effective only when it includes follow-up on whether the corrective action is actually working, and should also feed into checking whether a similar problem is occurring elsewhere in the organization. Also wrong: "a PMO uniformly and strongly controls every project"—in practice, the degree of involvement (from supportive to controlling) varies by organization. Also wrong: "IT governance is the same thing as individual project management"—it is the higher-level perspective that governs alignment of the whole portfolio with business strategy.
6.4.3Section summary
- Project audit is objective evaluation by an independent auditor; corrective recommendations are effective only with a clear owner, deadline, and follow-up
- The PMO handles standards, support, and control across the organization, with the degree of involvement varying by organization
- IT governance governs portfolio-wide strategic alignment from a management viewpoint, with audit and the PMO as its means of realization
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. A PMO receives a corrective recommendation from an independent auditor stating "the risk register has not been updated in three months and identified risks have gone stale." Which response should the PMO take first?
Q2. Similar risk-management stalling is found across multiple projects, and the cause turns out to be a structural problem: an unwieldy risk-management template. Which PMO response is most appropriate?
Q3. Each individual project is progressing smoothly, but management is concerned about "whether IT investment across multiple projects as a whole aligns with business strategy." Which mechanism most directly addresses this concern?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

