nerdexam
Isaca

CRISC · Question #178

Which of the following should be the GREATEST concern to a risk practitioner when process documentation is incomplete?

The correct answer is B. Inability to identify the risk owner. When process documentation is incomplete, the greatest concern for a risk practitioner is the inability to identify the risk owner.

Submitted by diego_uy· Apr 18, 2026Governance

Question

Which of the following should be the GREATEST concern to a risk practitioner when process documentation is incomplete?

Options

  • AInability to allocate resources efficiently
  • BInability to identify the risk owner
  • CInability to complete the risk register
  • DInability to identify process experts

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    78% (14)
  • C
    11% (2)
  • D
    6% (1)

Why each option

When process documentation is incomplete, the greatest concern for a risk practitioner is the inability to identify the risk owner.

AInability to allocate resources efficiently

While resource allocation might be impacted, it's a secondary concern compared to the fundamental lack of accountability that an unidentified risk owner represents.

BInability to identify the risk ownerCorrect

Incomplete process documentation makes it difficult to understand who is accountable for specific steps or outcomes within a process. Without a clear risk owner, accountability for managing, mitigating, or accepting risks associated with that process is ambiguous, leading to unmanaged risks and a breakdown in governance.

CInability to complete the risk register

The risk register can still be populated with identified risks, even if process documentation is incomplete, although the quality might suffer. The core issue is who *owns* those risks.

DInability to identify process experts

Identifying process experts might be challenging, but the critical problem is the lack of formal ownership and accountability for the risks themselves.

Concept tested: Importance of risk ownership

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/secure/security-governance-risk-compliance-strategies#risk-management-framework

Topics

#Risk ownership#Accountability#Risk management fundamentals#Process documentation

Community Discussion

No community discussion yet for this question.

Full CRISC Practice