CRISC · Question #526
Which of the following stakeholders define risk tolerance for an enterprise?
The correct answer is C. The board and executive management. The board and executive management are the stakeholders responsible for defining the risk tolerance for an enterprise.
Question
Which of the following stakeholders define risk tolerance for an enterprise?
Options
- AIT compliance and IT audit
- BRegulators and shareholders
- CThe board and executive management
- DEnterprise risk management (ERM)
How the community answered
(41 responses)- A7% (3)
- B2% (1)
- C88% (36)
- D2% (1)
Why each option
The board and executive management are the stakeholders responsible for defining the risk tolerance for an enterprise.
IT compliance and IT audit functions assess adherence to risk policies and controls but do not set the overarching risk tolerance for the enterprise.
Regulators and shareholders influence an organization's risk profile through external requirements and expectations, but they do not directly define the internal risk tolerance.
The board of directors and executive management are responsible for the overall governance and strategic direction of the enterprise. They establish the organization's risk appetite and risk tolerance, which represent the maximum level of risk the organization is willing to accept to achieve its objectives, and the acceptable deviation around those levels, respectively.
Enterprise Risk Management (ERM) programs implement and manage risks within the defined tolerance, but ERM itself does not define the tolerance; it operates within the boundaries set by leadership.
Concept tested: Risk tolerance ownership
Topics
Community Discussion
No community discussion yet for this question.