Courseiva
Risk Response and Reporting →mediumMultiple Select

CRISC Risk Response and Reporting Practice Question

An organization is integrating IT risk into its enterprise risk management (ERM) program. Which TWO of the following are key benefits of this integration?

⚠ Common exam trap

CRISC often tests the difference between benefits of integration (strategic alignment, consistent language) and misconceptions (eliminating reporting, guaranteeing mitigation, reducing appetite) — candidates frequently select absolute statements like 'eliminates' or 'guarantees' which are almost always wrong in risk management contexts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensures IT risk is considered in strategic decisions

Option D is correct because integrating IT risk into ERM ensures that technology-related exposures are evaluated alongside financial, operational, and strategic risks when leadership makes strategic decisions, so IT risk becomes part of governance rather than a siloed technical concern. Option E is correct because ERM integration establishes common risk terminology, scales, and criteria (for example, shared likelihood/impact definitions and risk appetite statements), giving the whole organization a consistent risk language for identifying, assessing, and reporting IT and non-IT risks. Option A is incorrect because integration does not inherently reduce the organization's risk appetite; risk appetite is set by leadership and integration only helps align IT risk with it. Option B is incorrect because IT risk still requires its own reporting detail and metrics even when aggregated into ERM. Option C is incorrect because no framework guarantees that all IT risks are mitigated; integration improves visibility and prioritization, not elimination of all risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reduces the overall risk appetite of the organization

    Why it's wrong here

    Integration aligns IT risk with enterprise tolerance; it does not lower the organisation's risk appetite, which is a board-level strategic decision made independently. The benefit is consistent, comparable risk reporting across the enterprise, not a reduction in appetite itself.

  • ✗

    Eliminates the need for separate IT risk reporting

    Why it's wrong here

    Integration folds IT risk into enterprise reporting, but IT-specific reporting to technology owners and regulators persists because ERM aggregates at a higher level. It is tempting because consolidated reporting reduces duplication, which is the genuine benefit integration delivers.

  • ✗

    Guarantees that all IT risks are mitigated

    Why it's wrong here

    Integration surfaces IT risk alongside other enterprise risks; it cannot guarantee mitigation, since risk treatment decisions and residual risk acceptance remain management choices. It is tempting because integration does improve visibility and prioritisation, which is the actual benefit sought in this scenario.

  • ✓

    Ensures IT risk is considered in strategic decisions

    Why this is correct

    Embedding IT risk into ERM feeds technology exposure into enterprise-level planning, so strategic decisions account for IT risk alongside financial and operational risk. This satisfies the integration goal of aligning IT risk with strategic decision-making.

  • ✓

    Provides a consistent risk language across the organization

    Why this is correct

    A shared taxonomy and scoring scale lets IT, finance and operations compare and aggregate risks consistently. This common language satisfies the integration goal of unified risk reporting across the enterprise, removing siloed terminology that obscures comparable exposures.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.