nerdexam
Isaca

CRISC · Question #334

Which of the following is the PRIMARY reason for a risk practitioner to report changes and trends in the IT risk profile to senior management?

The correct answer is B. To ensure IT risk is managed within acceptable limits. The primary reason for a risk practitioner to report changes and trends in the IT risk profile to senior management is to ensure IT risk is managed within acceptable limits.

Submitted by khalil_dz· Apr 18, 2026Risk Response and Reporting

Question

Which of the following is the PRIMARY reason for a risk practitioner to report changes and trends in the IT risk profile to senior management?

Options

  • ATo ensure risk owners understand their responsibilities
  • BTo ensure IT risk is managed within acceptable limits
  • CTo ensure the organization complies with legal requirements
  • DTo ensure the IT risk awareness program is effective

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    92% (24)
  • D
    4% (1)

Why each option

The primary reason for a risk practitioner to report changes and trends in the IT risk profile to senior management is to ensure IT risk is managed within acceptable limits.

ATo ensure risk owners understand their responsibilities

While risk owners need to understand their responsibilities, reporting to senior management serves the higher-level strategic governance function of overall risk oversight, not merely individual owner understanding.

BTo ensure IT risk is managed within acceptable limitsCorrect

Senior management bears the ultimate responsibility for defining the organization's risk appetite and ensuring that all risks, including IT risks, remain within these established acceptable limits. Reporting IT risk changes and trends enables senior management to monitor compliance with the risk appetite, make informed decisions regarding risk treatment strategies, and allocate resources effectively to maintain the desired risk posture.

CTo ensure the organization complies with legal requirements

Ensuring compliance with legal requirements is a critical aspect of risk management, but it falls under the broader objective of keeping risk within the acceptable organizational limits.

DTo ensure the IT risk awareness program is effective

Ensuring the effectiveness of an IT risk awareness program is an operational detail that supports risk management, not the primary strategic reason for senior management risk reporting.

Concept tested: Risk reporting to senior management

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-39.pdf

Topics

#Risk Reporting#Senior Management Communication#IT Risk Profile#Risk Monitoring

Community Discussion

No community discussion yet for this question.

Full CRISC Practice