Courseiva
hardMultiple ChoiceObjective-mapped

CRISC Practice Question: A multinational corporation operates in 15…

A multinational corporation operates in 15 countries with decentralized control monitoring systems. Each regional office uses different tools and processes for monitoring operational risks. The corporate risk team has consolidated quarterly reports, but the board recently raised concerns about inconsistencies and late identification of emerging risks. A root cause analysis revealed that regional monitoring teams define key risk indicators (KRIs) differently and report on different timeframes. Additionally, there is no centralized platform to aggregate data. The risk manager must recommend a solution that balances local autonomy with global visibility. Which option is the most effective?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement a centralized risk and control monitoring platform that aggregates data and enforces common reporting standards.

A centralized risk and control monitoring platform standardizes data and reporting while allowing local customization via configurable thresholds. Policy alone (A) doesn't enforce consistency; global standardization (C) might ignore local nuances; increasing meeting frequency (D) does not address data inconsistency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a policy requiring regional risk teams to follow the same KRI definitions and reporting schedule.

    Why it's wrong here

    Policies without tools/enforcement often fail; regions may not comply consistently.

  • Implement a centralized risk and control monitoring platform that aggregates data and enforces common reporting standards.

    Why this is correct

    Provides global visibility while allowing local input; addresses root cause of inconsistency.

  • Standardize monitoring tools across all regions globally.

    Why it's wrong here

    Forcing a single tool ignores regional needs and legacy investments; may be resisted.

  • Increase the frequency of board risk committee meetings to twice per month.

    Why it's wrong here

    More meetings do not solve the data inconsistency problem; information quality is the issue.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.