CGEIT · Question #397
Which of the following should be the FIRST action taken by a newly formed IT governance committee to ensure reports are compliant with regulations and identify key IT risks?
The correct answer is B. Develop and monitor IT key risk indicator (KRI) triggers. The first action for a newly formed IT governance committee to ensure regulatory compliance and identify risks is to develop and monitor IT Key Risk Indicator (KRI) triggers.
Question
Which of the following should be the FIRST action taken by a newly formed IT governance committee to ensure reports are compliant with regulations and identify key IT risks?
Options
- ADirect the development of a reporting communication plan.
- BDevelop and monitor IT key risk indicator (KRI) triggers.
- CTrain end users on regulation requirements.
- DImplement a mechanism to ensure reporting escalation.
How the community answered
(29 responses)- A14% (4)
- B55% (16)
- C7% (2)
- D24% (7)
Why each option
The first action for a newly formed IT governance committee to ensure regulatory compliance and identify risks is to develop and monitor IT Key Risk Indicator (KRI) triggers.
A reporting communication plan is important for disseminating information but does not, by itself, ensure compliance or identify risks; it is a subsequent step after risks and compliance requirements are understood.
KRIs provide early warning signals of increasing risk exposure, allowing the committee to proactively monitor potential non-compliance or emerging IT risks against regulatory requirements and take timely corrective actions. This proactive monitoring is fundamental to effective risk management and compliance.
Training end users is a crucial part of compliance, but it is an operational task that typically follows the identification of specific risks and requirements, which KRIs help to achieve.
A mechanism for reporting escalation is vital for incident response, but identifying the risks that might trigger such escalation, through KRIs, is a more fundamental and prior step for a governance committee.
Concept tested: IT risk management and governance
Topics
Community Discussion
No community discussion yet for this question.