Courseiva

CRISC Risk Response and Reporting Practice Question

When integrating IT risk into the enterprise risk management (ERM) program, the most important consideration is:

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mapping IT risks to enterprise risk categories

IT risk should be treated as a component of broader operational risk to ensure alignment with enterprise-level risk appetite and reporting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reporting IT risks only to the CIO

    Why it's wrong here

    Reporting IT risks solely to the CIO isolates them from the enterprise-wide risk register, so the board and other functions never see them aggregated alongside strategic and operational risks. It is tempting because the CIO owns IT delivery, and single-executive reporting suits purely operational IT issues; ERM integration instead requires enterprise-wide visibility.

  • ✗

    Eliminating IT risk reporting to the board

    Why it's wrong here

    Eliminating IT risk reporting to the board removes governance oversight, contradicting ERM integration, which requires IT risk to be aggregated and escalated alongside other enterprise risks. The option is tempting because consolidating reporting reduces duplication and board fatigue; that works when IT risk is already embedded within enterprise reporting, not when visibility is removed entirely.

  • ✓

    Mapping IT risks to enterprise risk categories

    Why this is correct

    Mapping IT risks to enterprise risk categories lets IT risk be aggregated, compared and reported alongside other risks within the ERM framework. Without that alignment, IT risk stays siloed and cannot inform enterprise-level risk appetite or reporting, which is the integration's core purpose.

  • ✗

    Using separate risk scoring for IT risks

    Why it's wrong here

    Separate scoring breaks comparability: IT risks cannot be aggregated or ranked against enterprise risks on a shared scale, defeating integration into the ERM register. It tempts because IT-specific scoring suits purely technical triage, where granularity and specialist metrics matter more than cross-domain comparability — the correct choice when IT operates its own risk register.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.