Courseiva
Risk Response and Reporting →mediumMultiple Choice

CRISC Risk Response and Reporting Practice Question

Which of the following is the PRIMARY purpose of integrating IT risk reporting into the enterprise risk management (ERM) program?

⚠ Common exam trap

ISACA often tests the misconception that ERM integration aims to replace or reduce IT-specific risk management activities, when in fact it seeks to elevate IT risk visibility to the enterprise level without eliminating specialized IT risk processes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To provide a holistic view of risk across the organization

Integrating IT risk reporting into the ERM program provides a holistic view of risk across the organization by aligning IT-specific risks with strategic, operational, and compliance risks. This integration ensures that decision-makers can prioritize and respond to risks based on their aggregate impact, rather than treating IT risks in isolation. The primary purpose is to enable a unified risk posture that supports enterprise-wide governance and resource allocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To reduce the frequency of IT risk reporting

    Why it's wrong here

    Integrating IT risk reporting into ERM does not reduce reporting frequency; it aligns IT risk with enterprise objectives and aggregates it at board level. Reducing frequency is tempting because consolidation can eliminate duplicate requests, but that is a by-product, not the primary purpose. Frequency reduction would be correct only where overlapping committee reports create redundant effort.

  • ✗

    To eliminate the need for IT risk assessments

    Why it's wrong here

    Integrating IT risk reporting into ERM aggregates IT exposure alongside financial, operational and strategic risks, informing enterprise-wide risk appetite decisions. Eliminating IT risk assessments removes the identification and analysis steps that generate the data feeding that reporting, leaving ERM blind to technology exposure. Assessments remain necessary; only their output is escalated into ERM reporting.

  • ✓

    To provide a holistic view of risk across the organization

    Why this is correct

    Integrating IT risk reporting into enterprise risk management aggregates technology exposures alongside financial, operational and compliance risks, so leadership sees interconnected exposures rather than a siloed technology list. This holistic aggregation is the primary purpose, enabling consistent prioritisation and comparison against the organisation's overall risk appetite.

  • ✗

    To replace IT risk management with ERM

    Why it's wrong here

    Integrating IT risk reporting into ERM aggregates technology exposure alongside financial and operational risks, informing enterprise-wide decisions. Replacing IT risk management with ERM would discard the technical controls, vulnerability data and IT-specific treatment plans that ERM cannot generate. ERM suits board-level aggregation; IT risk management remains the source discipline producing that data.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.