nerdexam
Isaca

CGEIT · Question #420

Which of the following should be the PRIMARY governance objective for selecting key risk indicators (KRIs) related to legal and regulatory compliance?

The correct answer is A. Identifying the risk of noncompliance. For legal and regulatory compliance, the primary objective of KRIs is to proactively identify and flag potential instances or conditions that could lead to noncompliance.

Submitted by khalil_dz· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following should be the PRIMARY governance objective for selecting key risk indicators (KRIs) related to legal and regulatory compliance?

Options

  • AIdentifying the risk of noncompliance
  • BDemonstrating sound risk management practices
  • CMeasuring IT alignment with enterprise risk management (ERM)
  • DEnsuring the effectiveness of IT compliance controls

How the community answered

(36 responses)
  • A
    92% (33)
  • B
    3% (1)
  • C
    6% (2)

Why each option

For legal and regulatory compliance, the primary objective of KRIs is to proactively identify and flag potential instances or conditions that could lead to noncompliance.

AIdentifying the risk of noncomplianceCorrect

The fundamental purpose of KRIs in the context of legal and regulatory compliance is to provide early warning signals for potential violations or breaches of laws, regulations, or internal policies. By identifying the risk of noncompliance, the organization can take timely corrective actions to prevent actual compliance failures and avoid associated penalties or reputational damage.

BDemonstrating sound risk management practices

While demonstrating sound risk management practices is a beneficial outcome, it is a broader objective; the specific primary purpose of KRIs for legal and regulatory compliance is to pinpoint noncompliance risks.

CMeasuring IT alignment with enterprise risk management (ERM)

Measuring IT alignment with ERM is important for overall risk strategy, but it is a higher-level objective compared to the direct, actionable purpose of compliance KRIs, which focus on specific regulatory adherence.

DEnsuring the effectiveness of IT compliance controls

Ensuring the effectiveness of IT compliance controls is a means to achieve compliance, and KRIs can help measure this, but the ultimate objective they serve in this context is to highlight where noncompliance risks might arise, indicating control failure or gaps.

Concept tested: KRI objective for compliance

Topics

#Key Risk Indicators#Legal and Regulatory Compliance#Governance Objectives#Risk Identification

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice