CRISC Risk Response and Reporting Practice Question
A multinational bank must report technology risk to its board risk committee each quarter. The committee has asked the risk team to strengthen the reporting so it drives decisions rather than just describing activity. Which TWO of the following changes would BEST achieve that objective? (Choose two.)
⚠ Common exam trap
The trap here is equating more data and longer narratives with better risk reporting for a board committee.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add trend analysis showing how key risk indicators have moved against their thresholds over several reporting periods.
Reporting that drives decisions must connect metrics to the limits leadership approved and show direction over time. Trend analysis against thresholds and breach status against appetite both give the committee a basis to act, such as approving remediation funding or accepting a documented exception. Expanded narratives, more metrics, or delegated authorship add volume or shift perspective without improving the committee's ability to decide.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Include a longer narrative describing every control test performed during the quarter.
Why it's wrong here
Volume of narrative does not improve decision quality. A detailed inventory of tests performed describes activity, not risk, and buries material issues in operational detail. Board committees need aggregated exposure, threshold breaches, and recommended actions; exhaustive test logs are better suited to management-level or audit reporting where the operational audience needs that granularity.
- ✓
Add trend analysis showing how key risk indicators have moved against their thresholds over several reporting periods.
Why this is correct
Trend analysis converts point-in-time metrics into a directional picture, letting the committee see whether exposure is improving or deteriorating relative to thresholds. That context supports decisions about resource allocation and escalation because members can judge whether current controls are working. Without trends, each report is an isolated snapshot and the committee cannot tell whether prior interventions produced results.
- ✗
Delegate the entire board report to the IT operations manager to reduce preparation time.
Why it's wrong here
Delegating authorship to an operational manager may speed preparation but risks a technology-centric view that omits business impact, appetite alignment, and enterprise context. Board reporting requires aggregation across domains and translation into business consequence. The risk function should own the report while drawing on operational data, so accountability and objectivity are preserved.
- ✓
Report each key risk indicator against its defined appetite and tolerance with clear breach status.
Why this is correct
Comparing indicators to approved appetite and tolerance levels tells the committee where the organization stands against the limits it set. Breach status immediately highlights exceptions requiring a decision, such as accepting, remediating, or reallocating budget. This framing links reporting directly to governance, because the committee can act on deviations rather than interpret raw numbers without a reference point.
- ✗
Increase the number of metrics reported from twenty to sixty to provide more coverage.
Why it's wrong here
Adding metrics without a link to decisions dilutes attention and can obscure the few indicators that matter. Board-level reporting succeeds through selectivity and relevance, not volume. Sixty metrics increase preparation effort and make it harder to spot genuine threshold breaches, which contradicts the committee's request for reporting that drives action rather than merely describes activity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.