Courseiva
IT Risk Assessment →mediumMultiple Choice

CRISC IT Risk Assessment Practice Question

A financial services firm has completed a risk assessment of its trading platform. The chief risk officer wants to ensure the assessment results are comparable across business units and that the reasoning behind each likelihood and impact rating is transparent to auditors. Which action BEST supports this objective?

⚠ Common exam trap

The trap here is equating a larger or more granular rating matrix with improved consistency, when consistency actually comes from defined criteria and documented rationale.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the rating scales and the specific criteria and evidence used to assign each likelihood and impact value

Comparability and auditability depend on defined rating scales, explicit criteria for each level, and documented evidence supporting each likelihood and impact assignment. These elements let different business units apply the same methodology and let auditors trace how each score was derived, which is more valuable than changing matrix size or centralizing decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the number of risks in the register to ensure no scenario is overlooked

    Why it's wrong here

    Expanding the register does not improve comparability of ratings or explain how values were assigned. A larger list may actually dilute focus and create inconsistent scoring if criteria remain undefined. The objective concerns the quality and transparency of rating decisions, not the sheer quantity of risks captured for the platform.

  • ✗

    Recalculate all risk scores using a 10×10 matrix instead of a 5×5 matrix

    Why it's wrong here

    A finer-grained matrix can allow more nuance, but it does not by itself standardize how raters interpret likelihood and impact, nor does it document the evidence behind each score. Without defined criteria and recorded rationale, comparability and auditability remain weak regardless of matrix size.

  • ✗

    Assign all risk scoring decisions to a single central analyst

    Why it's wrong here

    Centralizing scoring may improve consistency in the short term, but it removes business-unit context, creates a bottleneck, and still provides no documented criteria or evidence trail. Auditors would be unable to verify whether ratings reflect actual conditions, and comparability across units would depend on one person's judgment.

  • ✓

    Document the rating scales and the specific criteria and evidence used to assign each likelihood and impact value

    Why this is correct

    This is correct because consistent, well-documented rating criteria allow different business units to apply the same scales in comparable ways, and recording the evidence behind each rating gives auditors a clear rationale to review. It directly supports both comparability across units and traceability of assessment judgments for the trading platform risk register.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.