CRISC · Question #499
Which of the following should be reported periodically to the risk committee?
The correct answer is B. Emerging IT risk scenarios. The risk committee should be periodically informed about emerging IT risk scenarios to maintain strategic oversight of the organization's evolving risk landscape.
Question
Which of the following should be reported periodically to the risk committee?
Options
- ASystem risk and control matrix
- BEmerging IT risk scenarios
- CChanges to risk assessment methodology
- DAudit committee charter
How the community answered
(21 responses)- B95% (20)
- C5% (1)
Why each option
The risk committee should be periodically informed about emerging IT risk scenarios to maintain strategic oversight of the organization's evolving risk landscape.
A system risk and control matrix is an operational document useful for management and auditors but typically too detailed for periodic reporting to a strategic risk committee.
Emerging IT risk scenarios, such as new threats, technologies, or regulatory changes, can significantly alter an organization's overall risk profile. The risk committee requires this information to make informed strategic decisions, allocate resources, and adjust risk appetite or mitigation strategies proactively.
Changes to the risk assessment methodology are important for consistent risk evaluation but are usually reported when the change occurs, not necessarily on a periodic basis once implemented.
The audit committee charter defines the scope and responsibilities of the audit committee and is not typically a periodic report to the risk committee.
Concept tested: Risk committee reporting
Source: https://www.coso.org/Documents/COSO-ERM-Executive-Summary.pdf
Topics
Community Discussion
No community discussion yet for this question.