nerdexam
Isaca

CRISC · Question #470

Which of the following is the BEST approach for obtaining management buy-in to implement additional IT controls?

The correct answer is C. Describe IT risk impact on organizational processes in monetary terms. Describing IT risk impact in monetary terms is the best approach to gain management buy-in because it directly translates technical risks into quantifiable business consequences that executives understand.

Submitted by tyler.j· Apr 18, 2026Risk Response and Reporting

Question

Which of the following is the BEST approach for obtaining management buy-in to implement additional IT controls?

Options

  • AList requirements based on a commonly accepted IT risk management framework.
  • BProvide information on new governance, risk, and compliance (GRC) platform functionalities.
  • CDescribe IT risk impact on organizational processes in monetary terms.
  • DPresent new key risk indicators (KRIs) based on industry benchmarks.

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    15% (6)
  • C
    75% (30)
  • D
    8% (3)

Why each option

Describing IT risk impact in monetary terms is the best approach to gain management buy-in because it directly translates technical risks into quantifiable business consequences that executives understand.

AList requirements based on a commonly accepted IT risk management framework.

While referencing IT risk management frameworks is good practice, it may not resonate directly with management who need to see the business value or impact.

BProvide information on new governance, risk, and compliance (GRC) platform functionalities.

Providing information on GRC platform functionalities focuses on tools and technology rather further than the business impact or the problem that needs solving for management.

CDescribe IT risk impact on organizational processes in monetary terms.Correct

Management, especially senior leadership, primarily operates on a financial basis and understands the language of money. Translating IT risks into potential monetary losses (e.g., lost revenue, regulatory fines, recovery costs) clearly demonstrates the business impact, making the need for additional controls tangible and justifiable from a financial perspective.

DPresent new key risk indicators (KRIs) based on industry benchmarks.

Presenting new KRIs based on industry benchmarks can be informative, but without translating these indicators into their potential monetary impact on the organization, their urgency and relevance for management buy-in may be limited.

Concept tested: Communicating IT risk to management

Topics

#Risk communication#Management engagement#Monetary risk quantification#IT control justification

Community Discussion

No community discussion yet for this question.

Full CRISC Practice