nerdexam
Isaca

CRISC · Question #424

Which of the following is the MOST likely reason an organization would engage an independent reviewer to assess its IT risk management program?

The correct answer is D. To identify gaps in the alignment of IT risk management processes and strategy. Organizations engage independent reviewers to objectively identify discrepancies and gaps in the alignment of their IT risk management processes with their overall business strategy.

Submitted by ricky.ec· Apr 18, 2026Governance

Question

Which of the following is the MOST likely reason an organization would engage an independent reviewer to assess its IT risk management program?

Options

  • ATo ensure IT risk management is focused on mitigating emerging risk
  • BTo confirm that IT risk assessment results are expressed in quantitative terms
  • CTo evaluate threats to the organization's operations and strategy
  • DTo identify gaps in the alignment of IT risk management processes and strategy

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    12% (5)
  • C
    7% (3)
  • D
    79% (34)

Why each option

Organizations engage independent reviewers to objectively identify discrepancies and gaps in the alignment of their IT risk management processes with their overall business strategy.

ATo ensure IT risk management is focused on mitigating emerging risk

While addressing emerging risks is an important ongoing task of the risk management team, it is not the primary reason for an independent assessment of the overall *program's* alignment.

BTo confirm that IT risk assessment results are expressed in quantitative terms

The choice between quantitative or qualitative risk assessment is a methodological decision; an independent reviewer's primary role is to assess the program's effectiveness and alignment, not to dictate a specific reporting format.

CTo evaluate threats to the organization's operations and strategy

Evaluating specific threats is a core function performed *by* the risk management program; an independent reviewer assesses the *program's efficacy* in performing such evaluations and its overall strategic contribution.

DTo identify gaps in the alignment of IT risk management processes and strategyCorrect

An independent reviewer provides an unbiased perspective, crucial for identifying discrepancies between how the IT risk management program is designed and executed versus how it should support and align with the organization's overall business strategy and processes. This external validation helps ensure the program's effectiveness and strategic relevance, detecting any internal biases or blind spots.

Concept tested: Value of independent IT risk management program review

Source: https://learn.microsoft.com/en-us/compliance/regulatory/auditing-best-practices-guidance

Topics

#Independent Review#IT Risk Management Program#Strategic Alignment#Program Assessment

Community Discussion

No community discussion yet for this question.

Full CRISC Practice