nerdexam
Isaca

CRISC · Question #374

Which of the following is the PRIMARY reason to ensure policies and standards are properly documented within the risk management process?

The correct answer is B. It establishes a means for senior management to formally approve risk practices. Documenting policies and standards within risk management primarily provides a formal mechanism for senior management to review and approve the organization's risk practices, ensuring accountability and alignment.

Submitted by lars.no· Apr 18, 2026Governance

Question

Which of the following is the PRIMARY reason to ensure policies and standards are properly documented within the risk management process?

Options

  • AIt facilitates the use of a framework for risk management.
  • BIt establishes a means for senior management to formally approve risk practices.
  • CIt encourages risk-based decision making for stakeholders.
  • DIt provides a basis for benchmarking against industry standards.

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    75% (18)
  • C
    13% (3)
  • D
    8% (2)

Why each option

Documenting policies and standards within risk management primarily provides a formal mechanism for senior management to review and approve the organization's risk practices, ensuring accountability and alignment.

AIt facilitates the use of a framework for risk management.

While documented policies can align with frameworks, their primary purpose in documentation isn't just facilitation, but rather formalization and approval.

BIt establishes a means for senior management to formally approve risk practices.Correct

Documenting policies and standards is essential because it creates a formal record that senior management can review, understand, and then formally approve, thereby establishing official organizational commitment and accountability to the defined risk management practices. This formal approval signifies that the practices are endorsed by leadership and are mandatory for the organization.

CIt encourages risk-based decision making for stakeholders.

Documented policies help guide decision-making, but the *primary reason for documentation itself* is to make them official and subject to approval.

DIt provides a basis for benchmarking against industry standards.

Benchmarking might utilize documented policies for comparison, but the initial and primary reason for documentation is internal formalization and approval, not external comparison.

Concept tested: Importance of documenting risk policies

Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-iso-27001

Topics

#Risk Policies#Standards Documentation#Senior Management Approval#Risk Governance

Community Discussion

No community discussion yet for this question.

Full CRISC Practice