CRISC Risk Response and Reporting Practice Question
A retail company's IT risk manager is preparing a report for the board's audit committee. The report must summarize the current status of the top ten IT risks, the effectiveness of related controls, and any changes since the last quarter. Which of the following is the MOST important quality for this report to possess?
⚠ Common exam trap
The trap here is equating completeness or technical depth with good board reporting, when the real requirement is balanced, decision-useful information for a governance audience.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It provides a balanced view of risk exposure and control effectiveness, including areas where remediation is behind schedule.
The report's primary purpose is to enable the audit committee to oversee IT risk effectively. That requires a balanced presentation of exposures and control effectiveness, including unfavorable information such as overdue remediation. Reports skewed toward technical detail, only positive trends, or exhaustive risk lists fail to support informed governance and can hide material exposures from those accountable for oversight.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It includes every identified IT risk in the register to ensure completeness of disclosure.
Why it's wrong here
Including every risk in the register overwhelms the board and dilutes focus from the most significant exposures. Effective reporting prioritizes risks based on impact, likelihood, and appetite, using aggregation or appendices for lower-tier items. Completeness is achieved through a documented register, but the board report should concentrate on risks that require governance attention or decisions.
- ✓
It provides a balanced view of risk exposure and control effectiveness, including areas where remediation is behind schedule.
Why this is correct
Board reporting must be balanced and transparent, presenting both strengths and weaknesses. If the report omits risks with overdue remediation, the audit committee cannot fulfill its oversight role or challenge management. A balanced view supports informed governance decisions and aligns with the principle that risk reporting should enable stakeholders to understand actual exposure, not just favorable results.
- ✗
It focuses exclusively on risks that have decreased since the prior reporting period to show progress.
Why it's wrong here
Highlighting only improving risks creates a misleadingly positive picture and withholds information the audit committee needs to exercise oversight. Risks that have increased or remained static are equally important, especially if they approach or exceed appetite. Selective reporting undermines trust and can expose the organization to governance failures if undisclosed exposures later materialize.
- ✗
It uses detailed technical terminology to demonstrate the depth of the IT risk team's analysis.
Why it's wrong here
Board and audit committee members are typically not technical specialists, and dense jargon obscures rather than clarifies. Effective risk reporting translates technical exposure into business impact and uses language appropriate for governance audiences. Demonstrating analytical depth is better achieved through clear risk statements, trend data, and linkage to business objectives than through terminology that may confuse decision-makers.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.