hardMultiple ChoiceObjective-mapped
Standardizing KRI Definitions for Consistency
A global organization is consolidating risk data from multiple business units into a single enterprise risk management (ERM) system. The risk practitioner notices that KRIs for the same risk type (e.g., cybersecurity) are calculated differently across units. What is the BEST approach to ensure consistent and reliable risk monitoring and reporting?
Quick Answer
The answer is to establish a common definition and calculation methodology for each KRI across all business units. This approach directly addresses the root cause of inconsistency by ensuring that every unit applies the same formula and thresholds to the same risk type, which is essential for accurate consolidation into an enterprise risk management system. On the CRISC exam, this scenario tests your understanding of the KRIs domain, specifically the principle that reliable risk monitoring depends on standardized metrics rather than automated tools or unit-specific preferences. A common trap is to assume that technology, like automated data feeds, can fix definitional mismatches, but the exam emphasizes that methodology must come first. Remember the mnemonic “Define before you derive”—standardize the definition and calculation method before any data collection or aggregation occurs.
⚠ Common exam trap
Many exam-takers confuse KRIs with KPIs (option A) or believe that automated data feeds (option D) solve consistency issues, when in fact the core problem is the lack of a standardized measurement definition, not the data collection method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establish a common definition and calculation methodology for each KRI across all business units.
Consistent risk monitoring and reporting requires a standardized definition and calculation methodology for each KRI across all business units. Without this common baseline, the aggregated risk data in the ERM system will be incomparable and unreliable, leading to flawed decision-making. Establishing common definitions ensures that the same risk type (e.g., cybersecurity) is measured uniformly, enabling accurate trend analysis and risk aggregation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require all units to adopt a common set of key performance indicators for their control environment.
Why it's wrong here
KPIs measure performance, not risk levels.
- ✗
Allow each business unit to maintain its own KRI definitions but report explanations for variances.
Why it's wrong here
Variations still hinder consistent monitoring.
- ✓
Establish a common definition and calculation methodology for each KRI across all business units.
Why this is correct
Standardization is key to reliable aggregation.
- ✗
Implement automated data feeds from each unit's system to the ERM system without changing the KRI definitions.
Why it's wrong here
Automation does not solve the inconsistency issue.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has multiple business units each using different risk assessment methodologies. The risk committee wants consistent monitoring reports. What is the BEST approach to achieve consistency?
hard- ✓ A.Develop and mandate a standardized risk assessment methodology.
- B.Aggregate risks at the enterprise level using a common taxonomy.
- C.Require each business unit to adopt the same risk scoring scale.
- D.Create a centralized reporting template with predefined fields.
Why A: Mandating a standardized risk assessment methodology ensures that all business units apply the same criteria, scales, and processes for identifying, analyzing, and evaluating risks. This eliminates methodological inconsistencies at the source, enabling the risk committee to produce truly comparable and reliable monitoring reports across the enterprise.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.