CRISC Risk Governance and Frameworks 1 — Questions and Answers
Question 1: Which internationally recognized framework is MOST commonly used to align IT risk governance with enterprise risk management (ERM)?
- COSO ERM (Correct answer)
- ISO 9001
- ITIL v4
- PRINCE2
Correct answer: COSO ERM
COSO ERM provides an integrated framework that aligns IT risk management with broader enterprise risk governance objectives.
Question 2: The THREE lines of defense model assigns IT risk oversight responsibility to which line?
- Second line (risk management function) (Correct answer)
- First line (operational management)
- Third line (internal audit)
- Fourth line (external audit)
Correct answer: Second line (risk management function)
The second line of defense — the risk management function — is responsible for overseeing and monitoring IT risk across the organization.
Question 3: A risk appetite statement should PRIMARILY be approved by which organizational body?
- Board of Directors (Correct answer)
- Chief Information Officer
- IT Steering Committee
- Internal Audit Committee
Correct answer: Board of Directors
The Board of Directors is ultimately accountable for setting and approving the organization's risk appetite at the highest governance level.
Question 4: Which CRISC domain focuses on ensuring that risk management activities are integrated into the enterprise governance structure?
- IT Risk Identification
- IT Risk Assessment
- Risk Response and Reporting
- IT Risk Governance (Correct answer)
Correct answer: IT Risk Governance
The IT Risk Governance domain ensures risk management is embedded in the enterprise governance structure and aligned with business objectives.
Question 5: When developing a risk governance framework, which element BEST ensures accountability for risk decisions?
- Defined RACI matrix for risk roles (Correct answer)
- Automated risk monitoring tools
- Comprehensive risk register
- Regular vulnerability scans
Correct answer: Defined RACI matrix for risk roles
A RACI matrix (Responsible, Accountable, Consulted, Informed) explicitly assigns accountability for each risk-related decision and activity.
Question 6: Which statement BEST describes the relationship between risk tolerance and risk appetite?
- Risk tolerance is the acceptable deviation from risk appetite (Correct answer)
- Risk tolerance and risk appetite are synonymous terms
- Risk appetite is determined after risk tolerance is set
- Risk tolerance applies only to operational risks
Correct answer: Risk tolerance is the acceptable deviation from risk appetite
Risk tolerance represents the acceptable variation around the risk appetite threshold, allowing flexibility within defined boundaries.
Which internationally recognized framework is MOST commonly used to align IT risk governance with enterprise risk management (ERM)?