nerdexam
Isaca

CGEIT · Question #397

Which of the following should be the FIRST action taken by a newly formed IT governance committee to ensure reports are compliant with regulations and identify key IT risks?

The correct answer is B. Develop and monitor IT key risk indicator (KRI) triggers. The first action for a newly formed IT governance committee to ensure regulatory compliance and identify risks is to develop and monitor IT Key Risk Indicator (KRI) triggers.

Submitted by mateo_ar· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following should be the FIRST action taken by a newly formed IT governance committee to ensure reports are compliant with regulations and identify key IT risks?

Options

  • ADirect the development of a reporting communication plan.
  • BDevelop and monitor IT key risk indicator (KRI) triggers.
  • CTrain end users on regulation requirements.
  • DImplement a mechanism to ensure reporting escalation.

How the community answered

(29 responses)
  • A
    14% (4)
  • B
    55% (16)
  • C
    7% (2)
  • D
    24% (7)

Why each option

The first action for a newly formed IT governance committee to ensure regulatory compliance and identify risks is to develop and monitor IT Key Risk Indicator (KRI) triggers.

ADirect the development of a reporting communication plan.

A reporting communication plan is important for disseminating information but does not, by itself, ensure compliance or identify risks; it is a subsequent step after risks and compliance requirements are understood.

BDevelop and monitor IT key risk indicator (KRI) triggers.Correct

KRIs provide early warning signals of increasing risk exposure, allowing the committee to proactively monitor potential non-compliance or emerging IT risks against regulatory requirements and take timely corrective actions. This proactive monitoring is fundamental to effective risk management and compliance.

CTrain end users on regulation requirements.

Training end users is a crucial part of compliance, but it is an operational task that typically follows the identification of specific risks and requirements, which KRIs help to achieve.

DImplement a mechanism to ensure reporting escalation.

A mechanism for reporting escalation is vital for incident response, but identifying the risks that might trigger such escalation, through KRIs, is a more fundamental and prior step for a governance committee.

Concept tested: IT risk management and governance

Topics

#IT Governance Committee#Risk Identification#Key Risk Indicators (KRIs)#Compliance Monitoring

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice