CGEIT · Question #420
Which of the following should be the PRIMARY governance objective for selecting key risk indicators (KRIs) related to legal and regulatory compliance?
The correct answer is A. Identifying the risk of noncompliance. For legal and regulatory compliance, the primary objective of KRIs is to proactively identify and flag potential instances or conditions that could lead to noncompliance.
Question
Which of the following should be the PRIMARY governance objective for selecting key risk indicators (KRIs) related to legal and regulatory compliance?
Options
- AIdentifying the risk of noncompliance
- BDemonstrating sound risk management practices
- CMeasuring IT alignment with enterprise risk management (ERM)
- DEnsuring the effectiveness of IT compliance controls
How the community answered
(36 responses)- A92% (33)
- B3% (1)
- C6% (2)
Why each option
For legal and regulatory compliance, the primary objective of KRIs is to proactively identify and flag potential instances or conditions that could lead to noncompliance.
The fundamental purpose of KRIs in the context of legal and regulatory compliance is to provide early warning signals for potential violations or breaches of laws, regulations, or internal policies. By identifying the risk of noncompliance, the organization can take timely corrective actions to prevent actual compliance failures and avoid associated penalties or reputational damage.
While demonstrating sound risk management practices is a beneficial outcome, it is a broader objective; the specific primary purpose of KRIs for legal and regulatory compliance is to pinpoint noncompliance risks.
Measuring IT alignment with ERM is important for overall risk strategy, but it is a higher-level objective compared to the direct, actionable purpose of compliance KRIs, which focus on specific regulatory adherence.
Ensuring the effectiveness of IT compliance controls is a means to achieve compliance, and KRIs can help measure this, but the ultimate objective they serve in this context is to highlight where noncompliance risks might arise, indicating control failure or gaps.
Concept tested: KRI objective for compliance
Topics
Community Discussion
No community discussion yet for this question.