CRISC Information Technology and Security Practice Question
An organization is designing an IT risk management programme. Which of the following is the most critical component to ensure consistent identification and assessment of risks across the enterprise?
⚠ Common exam trap
CRISC often tests the distinction between governance elements (policy) and operational elements (methodology, process, register); candidates may incorrectly choose the policy because it sounds foundational, but the question asks for the component ensuring consistent identification and assessment, which is the methodology.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk assessment methodology
A risk assessment methodology provides a standardized approach for identifying, analyzing, and evaluating risks. It ensures that all business units use consistent criteria, scales, and processes, which is essential for comparing and aggregating risks across the enterprise. Without a common methodology, risk assessments become subjective and inconsistent, undermining the risk management program.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk assessment methodology
Why this is correct
A defined risk assessment methodology supplies common criteria, scales and scoring, so different business units identify and evaluate risks consistently. Without it, assessments vary by assessor and cannot be aggregated, failing the stem's requirement for enterprise-wide consistency in identification and assessment.
- ✗
Risk treatment process
Why it's wrong here
Risk treatment addresses responses to assessed risks, not the consistent identification and assessment that precedes treatment. It is tempting because treatment is a core programme phase, and it would be the correct answer if the question asked how the organisation selects and implements controls to modify identified risks.
- ✗
Risk management policy
Why it's wrong here
A policy states intent but does not itself enforce consistent identification and assessment; the risk register is the instrument that records and tracks risks uniformly. A policy is tempting because governance documents underpin programmes, yet it would be the answer when the question asks what establishes authority and mandate rather than the mechanism ensuring consistency.
- ✗
Risk register
Why it's wrong here
The risk register records identified risks and assessments but does not by itself ensure consistent identification across the enterprise; that requires a defined methodology or framework. It is tempting because it is the central artefact of risk management, and it would be correct if the question asked where risks and their assessments are documented and tracked.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.