CRISC Risk Response and Reporting Practice Question
An organization is integrating its IT risk program with the enterprise risk management (ERM) framework. Which THREE of the following activities support this integration?
⚠ Common exam trap
Many exam-takers think maintaining a separate IT risk register is acceptable for specialized IT risks, but CRISC emphasizes that integration requires sharing and aligning risk information across all levels, not isolating it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using consistent risk metrics and terminology across IT and enterprise levels
Option A is correct because using consistent risk metrics and terminology across IT and enterprise levels enables IT risk data to be aggregated, compared, and communicated within the ERM framework rather than being siloed in IT-specific language. Option B is correct because aligning IT risk appetite with enterprise risk appetite ensures IT risk tolerances and thresholds are derived from and consistent with the organization's overall risk appetite, which is a core requirement of ERM integration. Option C is correct because reporting IT risk as a component of broader operational risk allows IT risk to be consolidated into enterprise risk reporting, giving leadership a holistic view of risk exposure. Option D does not belong because maintaining a separate IT risk register not shared with ERM perpetuates silos and prevents aggregation and enterprise-level visibility. Option E does not belong because reporting IT risks only to the CIO without board visibility excludes key governance stakeholders and contradicts the top-down, board-engaged nature of ERM integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Using consistent risk metrics and terminology across IT and enterprise levels
Why this is correct
Shared metrics and terminology let IT risk data roll up into enterprise reporting without translation loss, enabling aggregation and comparison across the ERM framework. This consistency is a foundational integration activity, aligning how risk is measured and described at both levels.
- ✓
Aligning IT risk appetite with enterprise risk appetite
Why this is correct
Aligning IT risk appetite with enterprise risk appetite ensures technology risk tolerance stays within the boundaries set by the board, so IT decisions reflect organisational risk limits. This cascading alignment is a core integration activity linking IT risk governance to ERM.
- ✓
Reporting IT risk as a component of broader operational risk
Why this is correct
Reporting IT risk as a component of operational risk places technology exposures within the enterprise taxonomy, enabling the ERM function to aggregate and compare them alongside other operational risks. This consistent classification supports integrated enterprise-wide risk reporting.
- ✗
Maintaining a separate IT risk register not shared with ERM
Why it's wrong here
A separate IT risk register isolates IT risk data from enterprise risk aggregation, preventing the consolidated view integration requires. It is tempting because dedicated registers do give IT teams granular tracking of technical risks, making them the right choice when IT risks are too detailed or numerous for the enterprise register.
- ✗
Reporting IT risks only to the CIO without board visibility
Why it's wrong here
Restricting reporting to the CIO denies the board and ERM function the visibility needed to aggregate and govern IT risk enterprise-wide. It is tempting because CIO-only reporting does suit purely operational escalations, making it the right choice when a technical issue requires rapid executive action rather than board oversight.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.