nerdexam
Isaca

CRISC · Question #499

Which of the following should be reported periodically to the risk committee?

The correct answer is B. Emerging IT risk scenarios. The risk committee should be periodically informed about emerging IT risk scenarios to maintain strategic oversight of the organization's evolving risk landscape.

Submitted by deeparc· Apr 18, 2026Risk Response and Reporting

Question

Which of the following should be reported periodically to the risk committee?

Options

  • ASystem risk and control matrix
  • BEmerging IT risk scenarios
  • CChanges to risk assessment methodology
  • DAudit committee charter

How the community answered

(21 responses)
  • B
    95% (20)
  • C
    5% (1)

Why each option

The risk committee should be periodically informed about emerging IT risk scenarios to maintain strategic oversight of the organization's evolving risk landscape.

ASystem risk and control matrix

A system risk and control matrix is an operational document useful for management and auditors but typically too detailed for periodic reporting to a strategic risk committee.

BEmerging IT risk scenariosCorrect

Emerging IT risk scenarios, such as new threats, technologies, or regulatory changes, can significantly alter an organization's overall risk profile. The risk committee requires this information to make informed strategic decisions, allocate resources, and adjust risk appetite or mitigation strategies proactively.

CChanges to risk assessment methodology

Changes to the risk assessment methodology are important for consistent risk evaluation but are usually reported when the change occurs, not necessarily on a periodic basis once implemented.

DAudit committee charter

The audit committee charter defines the scope and responsibilities of the audit committee and is not typically a periodic report to the risk committee.

Concept tested: Risk committee reporting

Source: https://www.coso.org/Documents/COSO-ERM-Executive-Summary.pdf

Topics

#Risk reporting#Risk committee responsibilities#Emerging IT risks

Community Discussion

No community discussion yet for this question.

Full CRISC Practice