CRISC Risk Response and Reporting Practice Question
A global manufacturing company is designing its IT risk reporting program. The board has requested that reports be actionable, comparable over time, and aligned with the enterprise risk management framework. Which TWO of the following characteristics are MOST important for the IT risk reports to meet these objectives? (Choose two.)
⚠ Common exam trap
The trap here is assuming that more frequent or more detailed technical reporting automatically improves board-level risk reporting, when comparability and business context are what make reports actionable and ERM-aligned.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reports use consistent risk scoring criteria and definitions across all business units.
Actionable, comparable, and ERM-aligned reporting requires consistent risk scoring criteria and definitions so risks can be compared across units and over time. It also requires presenting risk in business context, linking technical findings to strategic objectives so the board can prioritize. Raw scan outputs and zero-residual-risk filters fail to provide meaningful governance information, and divergent local scales break comparability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reports include only risks that have been fully mitigated to zero residual risk.
Why it's wrong here
Reporting only fully mitigated risks would hide residual risk that the board needs to govern. Most risks cannot be reduced to zero, and suppressing those with residual exposure would misrepresent the organization's risk profile. Actionable reporting must show residual risk and the status of response plans, not just closed items.
- ✗
Reports are customized for each business unit using different risk scales to reflect local priorities.
Why it's wrong here
Using different risk scales across business units undermines comparability and prevents the board from aggregating or trending risk consistently. While local priorities matter, they should be expressed within a common enterprise risk framework. Customized scales fragment reporting and conflict with the requirement for comparable, ERM-aligned risk information.
- ✗
Reports are generated monthly using raw technical vulnerability scan outputs.
Why it's wrong here
Raw vulnerability scan outputs are voluminous, technical, and not directly comparable or actionable for a board. They lack business context and risk scoring, and monthly frequency alone does not ensure alignment with enterprise risk management. Effective reporting aggregates and translates technical data into meaningful risk information with consistent scoring.
- ✓
Reports use consistent risk scoring criteria and definitions across all business units.
Why this is correct
Consistent scoring criteria and definitions enable comparability across business units and over time. Without a common taxonomy and rating scale, the board cannot reliably compare risks or track trends. This directly supports the requirement for comparable reporting and alignment with the enterprise risk management framework, which depends on standardized risk language and metrics.
- ✓
Reports present risk information in business context, including potential impact on strategic objectives.
Why this is correct
Presenting risk in business context, such as impact on strategic objectives, makes reports actionable for the board. Directors can then prioritize and allocate resources based on how risks affect goals like revenue, compliance, or reputation. This aligns IT risk reporting with enterprise risk management by linking technical findings to business outcomes.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.