The correct answer is B. Determine if project goals were met as expected.
The primary purpose of a post-implementation review is to determine whether the project achieved its intended objectives, delivered the expected business value, met requirements, and produced the expected benefits. For a critical IT project, the most important audit focus is not only whether the project was delivered on time or within budget, but whether it actually achieved what the organization expected from it.
ISACA’s CISA Exam Content Outline specifically includes Post-implementation Review under Domain 3 and states that CISA tasks include conducting post-implementation reviews to determine whether project deliverables, controls, and requirements are met.
Option A is useful but not the primary focus. Business representation on the steering committee supports good governance, but it does not prove that the project achieved its objectives.
Option C is also important, but on-time and on-budget delivery does not necessarily mean project success. A project can be delivered on time and within budget but still fail to meet business requirements.
Option D is evidence of formal project closure, but stakeholder signoff alone does not provide enough assurance that the project goals and expected benefits were achieved.
ISACA also notes that benefit realization is measured after implementation and that a post-implementation review is usually recommended to quantify actual benefits from a program.
[References: ISACA CISA Exam Content Outline, Domain 3; ISACA guidance on post-implementation review and benefit realization., ===================, ]