A Certified Risk Architect (CRA) is tasked with designing a new enterprise risk management (ERM) framework for a multinational corporation. Which of the following international standards provides a principle-based approach and general guidelines for risk management, rather than a prescriptive, certifiable management system?
-
A
ISO 9001
-
B
Sarbanes-Oxley Act (SOX)
-
C
ISO 31000
-
D
COBIT Framework