CRISC Risk Response and Reporting Practice Question
When integrating IT risk into the enterprise risk management (ERM) program, the most important consideration is:
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mapping IT risks to enterprise risk categories
IT risk should be treated as a component of broader operational risk to ensure alignment with enterprise-level risk appetite and reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reporting IT risks only to the CIO
Why it's wrong here
Reporting IT risks solely to the CIO isolates them from the enterprise-wide risk register, so the board and other functions never see them aggregated alongside strategic and operational risks. It is tempting because the CIO owns IT delivery, and single-executive reporting suits purely operational IT issues; ERM integration instead requires enterprise-wide visibility.
- ✗
Eliminating IT risk reporting to the board
Why it's wrong here
Eliminating IT risk reporting to the board removes governance oversight, contradicting ERM integration, which requires IT risk to be aggregated and escalated alongside other enterprise risks. The option is tempting because consolidating reporting reduces duplication and board fatigue; that works when IT risk is already embedded within enterprise reporting, not when visibility is removed entirely.
- ✓
Mapping IT risks to enterprise risk categories
Why this is correct
Mapping IT risks to enterprise risk categories lets IT risk be aggregated, compared and reported alongside other risks within the ERM framework. Without that alignment, IT risk stays siloed and cannot inform enterprise-level risk appetite or reporting, which is the integration's core purpose.
- ✗
Using separate risk scoring for IT risks
Why it's wrong here
Separate scoring breaks comparability: IT risks cannot be aggregated or ranked against enterprise risks on a shared scale, defeating integration into the ERM register. It tempts because IT-specific scoring suits purely technical triage, where granularity and specialist metrics matter more than cross-domain comparability — the correct choice when IT operates its own risk register.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.