Comprehensive and Detailed In-Depth Explanation:IT application owners having sole responsibility for architecture approval (B) is a major concern because it indicates a lack of oversight and segregation of duties. EA decisions should be reviewed by a cross-functional governance body to ensure alignment with security, compliance, and business objectives. Other options: * The CIO chairing the review board (A) may indicate centralized leadership but is not inherently a risk. * EA governing non-IT projects (C) may indicate scope expansion but is not a security risk. * Security requirements being reviewed (D) is a best practice and not a concern. Reference: ISACA CISA Review Manual, IT Governance and Management of IT