nerdexam
Isaca

CGEIT · Question #134

The CIO in a large enterprise is seeking assurance that significant IT risk is being proactively monitored and does not exceed agreed risk tolerance levels. The BEST way to provide this ongoing…

The correct answer is C. key risk indicators (KRIs). To provide ongoing assurance that significant IT risk is proactively monitored and within tolerance, the best approach is to develop Key Risk Indicators (KRIs).

Submitted by andreas_gr· Apr 18, 2026Risk Optimization

Question

The CIO in a large enterprise is seeking assurance that significant IT risk is being proactively monitored and does not exceed agreed risk tolerance levels. The BEST way to provide this ongoing assurance is to require the development of:

Options

  • Aan IT risk appetite statement.
  • Ba risk management policy.
  • Ckey risk indicators (KRIs).
  • Da risk register.

How the community answered

(38 responses)
  • A
    11% (4)
  • B
    3% (1)
  • C
    82% (31)
  • D
    5% (2)

Why each option

To provide ongoing assurance that significant IT risk is proactively monitored and within tolerance, the best approach is to develop Key Risk Indicators (KRIs).

Aan IT risk appetite statement.

An IT risk appetite statement defines the level of risk an organization is willing to accept but does not provide ongoing monitoring or assurance of current risk levels.

Ba risk management policy.

A risk management policy establishes the rules and procedures for managing risk but does not offer direct, continuous monitoring of actual risk levels.

Ckey risk indicators (KRIs).Correct

Key Risk Indicators (KRIs) are metrics used to provide an early warning of increasing risk exposure in a specific area, enabling proactive monitoring and management to ensure risks do not exceed agreed tolerance levels.

Da risk register.

A risk register is a list of identified risks, their assessments, and mitigation plans, but it is a static record and does not inherently provide proactive, real-time monitoring of risk levels and tolerance adherence.

Concept tested: Proactive IT risk monitoring

Source: https://www.isaca.org/resources/isaca-journal/issues/2020/volume-5/kr-you-serious

Topics

#Key Risk Indicators (KRIs)#Risk Monitoring#IT Risk Management#Risk Assurance

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice