Courseiva

CRISC Risk Response and Reporting Practice Question

A multinational manufacturer is consolidating IT risk data from business units into a single enterprise risk report for the board. The risk manager must ensure the report supports effective risk-based decision making. Which TWO of the following characteristics are MOST important for the consolidated report to include? (Choose two.)

⚠ Common exam trap

The trap here is selecting exhaustive operational detail, such as full asset inventories or every control deficiency, instead of the comparability and tolerance context that make a consolidated report decision-useful.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Consistent risk rating criteria and definitions applied across all business units.

An enterprise risk report earns its value by enabling decisions, which requires two things: comparability and relevance to tolerance. Consistent rating criteria and definitions across business units make aggregated data trustworthy, while showing residual risk against approved tolerance tells the board where intervention is needed. Together they convert disparate unit-level data into a coherent enterprise view that supports prioritization, resource allocation, and formal risk acceptance decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Consistent risk rating criteria and definitions applied across all business units.

    Why this is correct

    Consolidating data from multiple units is meaningless if each unit rates likelihood and impact differently. Common criteria and definitions make ratings comparable, allow aggregation without distortion, and let the board see a true enterprise view. This consistency also supports trend analysis over time and fair prioritization across regions and functions, which is essential when resources are limited and trade-offs must be justified.

  • ✗

    A complete inventory of every IT asset and its configured technical settings.

    Why it's wrong here

    Asset inventories and configuration baselines are operational data that support risk assessment and control testing, but they overwhelm an enterprise risk report and do not directly inform board-level decisions. The board needs aggregation and context, not raw configuration detail. Including this level of granularity buries material risks in noise and lengthens reporting cycles without improving the quality of governance decisions.

  • ✗

    A forecast of IT budget spend for the next three fiscal years.

    Why it's wrong here

    Budget forecasts are planning documents that may inform response funding, but they are not a defining characteristic of an enterprise risk report. Including multi-year spend projections in a risk report conflates financial planning with risk reporting and can distract from exposure and tolerance discussions. The report should reference cost implications of responses where relevant, not carry the full budget forecast as a core element.

  • ✗

    Detailed descriptions of every control deficiency identified during the reporting period.

    Why it's wrong here

    Control deficiencies matter, but listing all of them individually is an operational audit artifact, not an enterprise risk report characteristic. The board needs deficiencies framed in terms of the risk they create, their effect on residual risk, and whether tolerance is breached. An exhaustive deficiency list obscures the aggregate picture and can shift the discussion toward tactical remediation rather than strategic risk decisions and resource allocation.

  • ✓

    Comparison of residual risk against approved risk tolerance for each material risk.

    Why this is correct

    Decision makers need to know not just what the risk is but whether it is acceptable. Placing residual risk alongside the approved tolerance shows where the organization is operating within bounds and where breaches require action. Without this comparison, the board cannot prioritize or authorize responses, and the report becomes a data listing rather than a decision-support tool. This characteristic directly enables risk-based governance and capital or resource allocation.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.