Courseiva

CRISC Information Technology and Security Practice Question

Which of the following is the PRIMARY purpose of a risk register in an IT risk management program?

⚠ Common exam trap

It's easy for candidates to confuse the risk register's primary purpose with secondary benefits like compliance or metrics, leading them to choose options that describe outputs or uses of the register rather than its core function of documenting and tracking risks and treatments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To document and track identified risks and their treatment plans

The risk register is the central repository for documenting identified risks, their assessed impact and likelihood, and the corresponding treatment plans (e.g., mitigate, accept, transfer, avoid). Its primary purpose is to provide a structured, living record that enables ongoing tracking, prioritization, and management of risk treatment activities throughout the IT risk management lifecycle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    To document and track identified risks and their treatment plans

    Why this is correct

    A risk register records each identified risk, its owner, likelihood and impact ratings, and the agreed treatment plan, giving management a single authoritative view for tracking and reporting. This documentation and tracking function is its primary purpose within the IT risk management programme.

  • ✗

    To provide a historical record of past incidents

    Why it's wrong here

    A risk register is forward-looking, capturing current and emerging risks with owners and responses; incident history is recorded in incident or problem management systems. It is tempting because past incidents inform likelihood ratings, and would be correct if the question asked where lessons learned from realised risks are retained for future assessments.

  • ✗

    To calculate key risk indicators (KRIs)

    Why it's wrong here

    A risk register records identified risks, owners, likelihood, impact and treatment status; KRIs are derived metrics calculated from that data, not its purpose. It is tempting because registers supply the source data for KRI reporting, and would be correct if the question asked where KRI thresholds and measurements are documented.

  • ✗

    To ensure compliance with regulatory requirements

    Why it's wrong here

    A risk register supports risk-based decisions; regulatory compliance is one input that may inform risk ratings, not the register's primary purpose. It is tempting because registers evidence due diligence to auditors, and would be correct if the question asked how an organisation demonstrates traceability of compliance obligations to identified risks.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.