Business Case Development and Feasibility Studies
Learn how auditors evaluate business cases and feasibility studies in IS acquisition, a key CISA exam topic.
Before any significant IT investment, organizations should conduct a feasibility study and develop a business case. For CISA candidates, understanding how to evaluate these artifacts is essential because they form the foundation for project governance and investment decisions.
The Purpose of a Feasibility Study
A feasibility study assesses whether a proposed project is viable from multiple perspectives:
- Technical Feasibility: Can the organization build or acquire the technology needed? Does the required expertise exist or can it be obtained?
- Economic Feasibility: Do the expected benefits justify the costs? What is the return on investment (ROI) and payback period?
- Operational Feasibility: Will the system be accepted by users? Can existing processes accommodate the new system?
- Schedule Feasibility: Can the project be completed within the required timeframe?
- Legal and Regulatory Feasibility: Does the project comply with applicable laws, regulations, and contractual obligations?
Components of a Business Case
A well-structured business case should include:
Problem Statement and Objectives
Clearly defines the business problem or opportunity and the objectives the project aims to achieve. Measurable success criteria should be established at this stage.
Cost-Benefit Analysis
Quantifies both tangible and intangible costs and benefits. Common financial metrics include Net Present Value (NPV), Internal Rate of Return (IRR), and Return on Investment (ROI). Intangible benefits such as improved customer satisfaction or competitive advantage should also be documented.
Risk Assessment
Identifies potential risks to project success and proposes mitigation strategies. This should cover technical risks, organizational risks, and external risks.
Alternatives Analysis
Evaluates at least two or three alternatives, including the option of doing nothing. Each alternative should be assessed against the same criteria for fair comparison.
Audit Considerations
IS auditors reviewing business cases and feasibility studies should assess:
- Whether the analysis was conducted by qualified individuals with appropriate independence
- Whether assumptions are reasonable, documented, and supported by evidence
- Whether all relevant costs (including ongoing maintenance and support) are included
- Whether risks are realistically assessed rather than minimized to gain approval
- Whether appropriate management levels approved the business case
Common Pitfalls
Auditors frequently find that organizations underestimate costs, overestimate benefits, or fail to consider the total cost of ownership. Another common issue is confirmation bias, where the feasibility study is conducted to justify a decision that has already been made rather than to objectively evaluate alternatives.
CISA Exam Relevance
Exam questions may ask candidates to identify the most significant weakness in a business case or determine what an auditor should recommend when a feasibility study is missing key elements. Understanding the components and purpose of these documents is critical for success.