Courseiva
hardMultiple Choice

CRISC Practice Question: A large bank has implemented a sophisticated risk…

A large bank has implemented a sophisticated risk and control monitoring system with multiple dashboards and automated reporting for key risk indicators (KRIs). However, the board of directors has been receiving conflicting KRI reports from different business units (e.g., retail banking, corporate lending, and wealth management). For example, the fraud KRI shows a high risk in retail but low risk in wealth management, yet both units use the same underlying data source. The chief risk officer (CRO) is concerned that the board is losing confidence in the risk reporting. An investigation reveals that each business unit defines and calculates KRIs differently, uses different thresholds, and reports on different schedules. What is the most likely root cause and the best remediation?

⚠ Common exam trap

CRISC often tests the misconception that reporting frequency or board training is the root cause of inconsistent risk reporting, when the real issue is lack of standardized KRI definitions and calculation methodologies — the exam expects you to identify governance and standardization gaps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The KRI definitions and calculation methods are not standardized across business units.

The root cause of conflicting KRI reports is that each business unit defines and calculates KRIs differently, uses different thresholds, and reports on different schedules. This lack of standardization leads to inconsistent risk measurements, even when using the same underlying data source. The best remediation is to standardize KRI definitions, calculation methods, thresholds, and reporting frequencies across all business units to ensure consistent and comparable risk reporting to the board.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The reporting frequency is inadequate; monthly reports should be weekly.

    Why it's wrong here

    Frequency cannot reconcile conflicting values for the same fraud KRI drawn from one data source; weekly reporting of inconsistent definitions still conflicts. Increasing cadence is tempting because stale data hampers oversight, and it would be correct if units shared definitions but reported too infrequently for the board.

  • ✗

    The data sources for KRIs are inconsistent across business units.

    Why it's wrong here

    The stem states both units use the same underlying data source, so inconsistent sources is contradicted by the evidence; the divergence stems from differing KRI definitions, thresholds and schedules. It is tempting because source inconsistency commonly causes conflicting metrics, and it would be correct if units genuinely drew from separate systems.

  • ✗

    The board members are misinterpreting the KRI reports due to lack of training.

    Why it's wrong here

    Board misinterpretation cannot explain units calculating the same fraud KRI differently from one data source; the stem already identifies inconsistent definitions, thresholds and schedules. Training is tempting because unclear dashboards do cause confusion, and it would be correct if reports were consistent but poorly explained.

  • ✓

    The KRI definitions and calculation methods are not standardized across business units.

    Why this is correct

    Divergent KRI definitions, calculation methods, thresholds and reporting schedules across business units produce inconsistent figures from identical source data, destroying board confidence. Standardising definitions, formulas and thresholds centrally, with a unified reporting cadence, restores comparability and credibility of enterprise risk reporting.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.