Courseiva
easyMultiple Choice

CRISC Practice Question: Is designing a risk indicator monitoring program…

An organization is designing a risk indicator monitoring program for its key financial risks. Which of the following is the BEST example of a key risk indicator (KRI) for credit risk?

⚠ Common exam trap

Many exam-takers confuse KRIs with KPIs or operational metrics, selecting a generic performance measure (like training completion or uptime) instead of a risk-specific indicator that directly quantifies credit exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Percentage of loans that are in default or non-performing.

A key risk indicator (KRI) for credit risk must directly measure the likelihood or impact of a borrower failing to meet their obligations. The percentage of loans that are in default or non-performing is a direct, quantitative measure of credit risk exposure, as it reflects the actual realization of credit losses. This aligns with the CRISC focus on monitoring risk levels to trigger timely responses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Percentage of loans that are in default or non-performing.

    Why this is correct

    Non-performing and defaulted loans directly measure realised credit deterioration, quantifying exposure to borrower failure. As a KRI it tracks the likelihood and magnitude of credit loss, giving forward-looking warning of rising counterparty risk rather than operational or market indicators.

  • ✗

    Number of employees who completed cybersecurity training.

    Why it's wrong here

    Cybersecurity training completion measures human security awareness, which does not indicate credit exposure or borrower default likelihood. It is tempting because training metrics are easy to collect and quantify, and they would be a valid KRI for information security or operational risk rather than credit risk.

  • ✗

    Percentage of network uptime over the past month.

    Why it's wrong here

    Network uptime measures technology availability, which does not reflect credit exposure, default rates or counterparty quality. It is tempting because uptime is a clean, continuously measurable metric, and it would be a valid KRI for operational or IT availability risk rather than credit risk.

  • ✗

    Employee turnover rate in the finance department.

    Why it's wrong here

    Finance-department turnover reflects staffing and operational stability, not the creditworthiness of borrowers or counterparties. It is tempting because turnover data is readily available and quantifiable, and it would serve as a KRI for operational or key-personnel risk rather than credit risk.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.