CRISC Risk Response and Reporting Practice Question
Which THREE of the following are components of an effective IT risk reporting structure for a large enterprise? (Select THREE)
⚠ Common exam trap
It's easy for candidates to confuse the frequency and audience for risk reporting, assuming that more frequent reporting to higher levels is always better, when in fact the board needs less frequent, strategic summaries and operational staff need more frequent, detailed updates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Strategic risk reporting to the board on a semi-annual basis
Option A is correct because strategic risk reporting to the board on a semi-annual basis aligns with the board's governance and oversight role, giving directors a periodic, high-level view of enterprise risk posture without overwhelming them with operational detail. Option B is correct because tactical risk reporting to the CISO on a quarterly basis matches the CISO's responsibility for managing the information security risk program and provides a cadence suitable for tracking risk treatment progress and emerging threats. Option E is correct because operational risk reporting to IT management on a weekly basis supports timely decision-making on day-to-day control failures, incidents, and remediation activities that require rapid attention. Option C is not appropriate because annual reporting to IT operational staff is too infrequent for the operational level, where risks change quickly and require continuous awareness. Option D is not appropriate because daily risk reporting to the board is excessive and misaligned with the board's strategic oversight role, which relies on summarized, periodic reporting rather than daily operational data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Strategic risk reporting to the board on a semi-annual basis
Why this is correct
Board-level strategic risk reporting on a semi-annual cadence matches the governance oversight layer of a large enterprise, giving directors aggregated, forward-looking risk exposure without operational noise. This satisfies the stem's requirement for a reporting structure spanning strategic, tactical and operational tiers.
- ✓
Tactical risk reporting to the CISO on a quarterly basis
Why this is correct
Quarterly tactical reporting to the CISO aligns risk information with the executive who owns the IT risk programme, at a cadence matching decision cycles. This satisfies the stem's requirement for a defined reporting structure covering strategic, tactical and operational levels.
- ✗
Annual risk reporting to IT operational staff
Why it's wrong here
Annual reporting cannot support operational risk decisions, which require continuous visibility as conditions change; the reporting cadence fails the enterprise's need for timely escalation and treatment. It is tempting because periodic reporting suits governance and board oversight, where an annual summary of aggregated risk posture is genuinely the correct choice.
- ✗
Daily risk reporting to the board
Why it's wrong here
Boards need aggregated risk insight at a strategic cadence, typically quarterly or via escalation, so daily reporting floods them with operational noise and dilutes governance oversight. Daily reporting suits operational teams managing live incidents, not board-level risk governance.
- ✓
Operational risk reporting to IT management on a weekly basis
Why this is correct
Weekly operational risk reporting to IT management provides the high-frequency, granular visibility needed to act on control failures and emerging issues. This satisfies the stem's requirement for a layered reporting structure spanning strategic, tactical and operational tiers.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.