Why pre-screen IT governance managers before the interview
Governance fails without making a sound. A framework gets adopted, policies get written, an annual attestation gets signed, and nothing about how technology decisions are made actually changes. Managers worth hiring can point to a control that people follow because it was designed around how the work happens. A short screen asks for one adopted control and one that was rejected.
What actually matters when screening IT Governance Manager candidates
- 01
Technical depth
Check command of COBIT 2019, ISO 27001 Annex A, NIST CSF and SOX ITGC control design; ask how they map controls to a policy framework and control library.
- 02
Real incidents and findings
Probe audits they personally steered: SOC 2 Type II readiness, internal audit findings, regulator exams, and how many exceptions closed within remediation deadlines.
- 03
Risk judgement
Test how they rank items on a risk register: inherent versus residual scoring, risk appetite thresholds, and when they signed off a formal exception or acceptance.
- 04
Getting things fixed
Assess how they drove remediation with engineering and vendor owners: control ownership assignment, GRC tooling (Archer, ServiceNow IRM, LogicGate), and steering committee escalation.
Pre-screening questions to ask IT Governance Manager candidates
12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.
Programmes that landed
3 questions01Can you describe a successful IT governance project you led in a previous role?
Listen forA programme with a change in behaviour attached, not only a framework adopted on paper.
Success measured by documents produced, or programmes that ended at policy approval.
02Can you share your experience developing and implementing governance strategies?
Listen forStrategy sequenced by risk with early wins delivered, rather than everything attempted at once.
Multi-year roadmaps with nothing delivered, or strategy written without operational input.
03Can you describe a challenging governance project and how you tackled it?
Listen forReal resistance encountered, with what they conceded and what they held firm on described.
Challenges described as a lack of maturity, or no compromise they had to make.
Framework fits the risk
3 questions04Do you have experience implementing a recognised IT compliance framework?
Listen forFramework applied proportionately, with controls scoped to the risks the organisation actually carries.
Frameworks applied in full regardless of size, or controls copied without tailoring.
05What is your experience with IT auditing and risk assessment?
Listen forAudits they prepared for or ran, with findings tracked to closure rather than logged and left.
Findings accepted repeatedly without remediation, or audit treated as an adversarial exercise.
06Do you have experience drafting IT policies and procedures?
Listen forPolicies written to be followed, short enough to read and matched to how the work is done.
Policy libraries nobody reads, or documents copied from templates without adaptation.
Risk decisions recorded
3 questions07Do you have experience with cybersecurity management and data privacy regulation?
Listen forSecurity and privacy obligations translated into specific controls, with ownership assigned clearly.
Obligations listed without controls, or ownership left with governance rather than the business.
08Which regulatory requirements do you consider most critical in IT governance?
Listen forPriorities reasoned from the organisation's actual exposure, not a general list of regulations.
Every requirement treated as equally critical, or priorities that ignore the business context.
09What tools and methods do you use to track IT performance and control effectiveness?
Listen forControl effectiveness tested rather than attested, with evidence collected as work happens.
Compliance measured by self-assessment, or evidence assembled only before an audit.
Business actually complies
3 questions10Describe persuading stakeholders to accept a governance policy or decision.
Listen forThe case made in terms of the team's own risk, with the control adjusted to fit their workflow.
Compliance achieved through mandate alone, or objections overruled without adjustment.
11How do you communicate governance initiatives to senior executives?
Listen forRisk expressed in business terms with options and costs, so executives can make a real decision.
Reporting in control language, or executives asked to approve without a stated trade-off.
12Do you have experience negotiating with IT vendors and managing service agreements?
Listen forService levels negotiated with remedies that matter, and vendor performance actually reviewed.
Agreements signed without measurable commitments, or vendor performance never reviewed.
How to score responses
Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.
Technical depth
35%5Names specific control objectives, explains ITGC scoping for change, access and operations, and distinguishes framework mapping from copy-paste adoption.
Real incidents and findings
30%5Cites named audits with finding counts, root causes, closure rates, and evidence packs they built rather than inherited from predecessors.
Risk judgement
20%5Describes a defensible scoring method, names the accountable risk owner, and gives an exception they refused along with the reasoning.
Getting things fixed
15%5Shows overdue actions falling through named owners, tracked workflows, and board or steering reporting, not repeated reminder emails.
A framework can be adopted while nothing about decisions changes. A one-way video screen asks which control people follow.
Try it on HirevireScreening FAQ
Process basics
How long should a pre-screening round for this role take?
Fifteen minutes across eight to ten questions, answered async. Enough to establish programmes they ran, test their framework and audit knowledge, and check how they win business acceptance.
How technical does this role need to be?
Enough to judge whether a control is workable for the engineers who must follow it. A manager without that will write policy that gets formally accepted and informally ignored.
Evaluating answers
What is the strongest signal when screening this role?
A control people actually follow. Managers who deliver describe designing around existing workflow. Anyone whose evidence is a policy library has produced documents rather than governance.
How do I judge their proportionality?
Ask what they deliberately did not control. Sound answers show risk-based prioritisation. Anyone applying a framework in full regardless of the organisation's size will create resistance everywhere.
























