CRISC IT Risk Assessment Practice Question
A financial services firm has completed a risk assessment of its trading platform. The chief risk officer wants to ensure the assessment results are comparable across business units and that the reasoning behind each likelihood and impact rating is transparent to auditors. Which action BEST supports this objective?
⚠ Common exam trap
The trap here is equating a larger or more granular rating matrix with improved consistency, when consistency actually comes from defined criteria and documented rationale.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the rating scales and the specific criteria and evidence used to assign each likelihood and impact value
Comparability and auditability depend on defined rating scales, explicit criteria for each level, and documented evidence supporting each likelihood and impact assignment. These elements let different business units apply the same methodology and let auditors trace how each score was derived, which is more valuable than changing matrix size or centralizing decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the number of risks in the register to ensure no scenario is overlooked
Why it's wrong here
Expanding the register does not improve comparability of ratings or explain how values were assigned. A larger list may actually dilute focus and create inconsistent scoring if criteria remain undefined. The objective concerns the quality and transparency of rating decisions, not the sheer quantity of risks captured for the platform.
- ✗
Recalculate all risk scores using a 10×10 matrix instead of a 5×5 matrix
Why it's wrong here
A finer-grained matrix can allow more nuance, but it does not by itself standardize how raters interpret likelihood and impact, nor does it document the evidence behind each score. Without defined criteria and recorded rationale, comparability and auditability remain weak regardless of matrix size.
- ✗
Assign all risk scoring decisions to a single central analyst
Why it's wrong here
Centralizing scoring may improve consistency in the short term, but it removes business-unit context, creates a bottleneck, and still provides no documented criteria or evidence trail. Auditors would be unable to verify whether ratings reflect actual conditions, and comparability across units would depend on one person's judgment.
- ✓
Document the rating scales and the specific criteria and evidence used to assign each likelihood and impact value
Why this is correct
This is correct because consistent, well-documented rating criteria allow different business units to apply the same scales in comparable ways, and recording the evidence behind each rating gives auditors a clear rationale to review. It directly supports both comparability across units and traceability of assessment judgments for the trading platform risk register.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.