Courseiva

CRISC Risk Response and Reporting Practice Question

A retail company's IT risk manager is preparing a report for the board's audit committee. The report must summarize the current status of the top ten IT risks, the effectiveness of related controls, and any changes since the last quarter. Which of the following is the MOST important quality for this report to possess?

⚠ Common exam trap

The trap here is equating completeness or technical depth with good board reporting, when the real requirement is balanced, decision-useful information for a governance audience.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It provides a balanced view of risk exposure and control effectiveness, including areas where remediation is behind schedule.

The report's primary purpose is to enable the audit committee to oversee IT risk effectively. That requires a balanced presentation of exposures and control effectiveness, including unfavorable information such as overdue remediation. Reports skewed toward technical detail, only positive trends, or exhaustive risk lists fail to support informed governance and can hide material exposures from those accountable for oversight.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It includes every identified IT risk in the register to ensure completeness of disclosure.

    Why it's wrong here

    Including every risk in the register overwhelms the board and dilutes focus from the most significant exposures. Effective reporting prioritizes risks based on impact, likelihood, and appetite, using aggregation or appendices for lower-tier items. Completeness is achieved through a documented register, but the board report should concentrate on risks that require governance attention or decisions.

  • ✓

    It provides a balanced view of risk exposure and control effectiveness, including areas where remediation is behind schedule.

    Why this is correct

    Board reporting must be balanced and transparent, presenting both strengths and weaknesses. If the report omits risks with overdue remediation, the audit committee cannot fulfill its oversight role or challenge management. A balanced view supports informed governance decisions and aligns with the principle that risk reporting should enable stakeholders to understand actual exposure, not just favorable results.

  • ✗

    It focuses exclusively on risks that have decreased since the prior reporting period to show progress.

    Why it's wrong here

    Highlighting only improving risks creates a misleadingly positive picture and withholds information the audit committee needs to exercise oversight. Risks that have increased or remained static are equally important, especially if they approach or exceed appetite. Selective reporting undermines trust and can expose the organization to governance failures if undisclosed exposures later materialize.

  • ✗

    It uses detailed technical terminology to demonstrate the depth of the IT risk team's analysis.

    Why it's wrong here

    Board and audit committee members are typically not technical specialists, and dense jargon obscures rather than clarifies. Effective risk reporting translates technical exposure into business impact and uses language appropriate for governance audiences. Demonstrating analytical depth is better achieved through clear risk statements, trend data, and linkage to business objectives than through terminology that may confuse decision-makers.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.