Courseiva

CRISC Risk Response and Reporting Practice Question

A risk practitioner is defining key risk indicators (KRIs) for the organization's third-party risk program after several supplier outages disrupted operations. Which TWO characteristics are essential for these KRIs to be effective for the risk committee? (Choose two.)

⚠ Common exam trap

The trap here is selecting indicators that are easy to collect, such as supplier counts, instead of ones that actually signal risk exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Each indicator is measurable from data that can be collected reliably and repeatedly.

Effective KRIs are measurable from reliable, repeatable data and are linked to thresholds that trigger defined action. Those two properties turn a metric into a decision-support tool for the risk committee. Activity counts, subjective ratings, and annual-only reviews lack the objectivity, relevance, and timeliness needed to warn about third-party disruption before it affects operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Each indicator reflects the total number of suppliers onboarded during the reporting period.

    Why it's wrong here

    Onboarding volume is an operational throughput measure, not an indicator of risk exposure or control effectiveness. A rising count of new suppliers does not by itself signal increasing or decreasing third-party risk, and it gives the committee no insight into outage likelihood or impact. Effective KRIs must relate to the risk being monitored, not merely to activity levels in the procurement process.

  • ✗

    Each indicator is reviewed only during the annual enterprise risk assessment cycle.

    Why it's wrong here

    Annual review is far too infrequent for indicators meant to provide early warning of supplier disruption. Third-party risk conditions change continuously, and a yearly glance would let exposure build unchecked between assessments. KRIs must be monitored at a cadence matched to how quickly the underlying risk can materialize, with more frequent reporting for critical suppliers.

  • ✓

    Each indicator is measurable from data that can be collected reliably and repeatedly.

    Why this is correct

    A KRI is only useful if it can be calculated consistently from dependable sources; otherwise trends and thresholds are meaningless. Reliable, repeatable measurement lets the risk committee compare periods, detect deterioration, and trust the signal. Indicators built on anecdotal data or manual estimates that vary by analyst introduce noise and erode confidence, defeating the purpose of monitoring third-party risk over time.

  • ✓

    Each indicator is tied to a defined risk threshold that triggers a specific escalation or response.

    Why this is correct

    Thresholds convert a metric into a decision tool. Without agreed limits and a defined response when they are breached, the committee sees numbers but has no basis for action. Linking each KRI to escalation criteria ensures that deterioration in third-party risk prompts timely intervention, resource allocation, or treatment decisions rather than passive observation of a dashboard.

  • ✗

    Each indicator is expressed as a qualitative rating assigned by the relationship manager.

    Why it's wrong here

    Purely subjective ratings drift between assessors and over time, making trend analysis and threshold comparison unreliable. While qualitative input has value alongside quantitative data, a KRI built solely on a manager's impression cannot be validated or reproduced. For committee-level oversight of third-party outages, objective, consistently collected measures provide the defensible signal that subjective ratings alone cannot.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.