nerdexam
Isaca

CRISC · Question #598

During the creation of an organization's IT risk management program, the BEST time to identify key risk indicators (KRIs) is while:

The correct answer is C. Developing a risk monitoring process. The best time to identify Key Risk Indicators (KRIs) during the creation of an IT risk management program is while developing the risk monitoring process. KRIs are essential metrics used to track and report on changes in risk exposure over time, directly supporting the monitoring

Submitted by deeparc· Apr 18, 2026Risk Response and Reporting

Question

During the creation of an organization's IT risk management program, the BEST time to identify key risk indicators (KRIs) is while:

Options

  • AInterviewing data owners
  • BReviewing risk response plans with internal audit
  • CDeveloping a risk monitoring process
  • DReviewing an external risk assessment

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    77% (27)
  • D
    14% (5)

Why each option

The best time to identify Key Risk Indicators (KRIs) during the creation of an IT risk management program is while developing the risk monitoring process. KRIs are essential metrics used to track and report on changes in risk exposure over time, directly supporting the monitoring function.

AInterviewing data owners

Interviewing data owners helps identify *risks* and assets, but not specifically the indicators for *monitoring* the ongoing status or changes in those risks.

BReviewing risk response plans with internal audit

Reviewing risk response plans with internal audit occurs *after* risks are identified and responses defined; KRIs are for ongoing monitoring of the effectiveness of those responses and the overall risk posture.

CDeveloping a risk monitoring processCorrect

Key Risk Indicators (KRIs) are metrics used to provide an early signal of increasing risk exposure, making them integral to an effective risk monitoring process. Therefore, identifying KRIs is best done concurrently with or as a foundational step of developing the risk monitoring process, as they define what needs to be tracked and reported for ongoing risk awareness.

DReviewing an external risk assessment

Reviewing an external risk assessment provides valuable input on potential risks, but the *identification* of specific internal KRIs is a distinct step tied to the organization's own monitoring requirements.

Concept tested: Key Risk Indicator (KRI) identification

Source: https://www.isaca.org/resources/isaca-journal/issues/2012/volume-3/key-risk-indicators-kriss-and-key-performance-indicators-kpis

Topics

#Key Risk Indicators (KRIs)#Risk Monitoring#IT Risk Program Development

Community Discussion

No community discussion yet for this question.

Full CRISC Practice