nerdexam
Isaca

CRISC · Question #637

Who is accountable for the process when an IT stakeholder operates a key control to address a risk scenario?

The correct answer is A. Risk owner. When an IT stakeholder operates a key control to address a risk scenario, the risk owner is ultimately accountable for the overall risk management process.

Submitted by fatema_kw· Apr 18, 2026Risk Response and Reporting

Question

Who is accountable for the process when an IT stakeholder operates a key control to address a risk scenario?

Options

  • ARisk owner
  • BIT manager
  • CSystem owner
  • DData custodian

How the community answered

(53 responses)
  • A
    91% (48)
  • B
    6% (3)
  • C
    2% (1)
  • D
    2% (1)

Why each option

When an IT stakeholder operates a key control to address a risk scenario, the risk owner is ultimately accountable for the overall risk management process.

ARisk ownerCorrect

The risk owner is a designated individual or entity responsible for managing a specific risk, including ensuring that appropriate controls are in place, effective, and monitored. While an IT stakeholder may *operate* a control, the risk owner retains ultimate accountability for the risk and its management process.

BIT manager

An IT manager might be responsible for the IT operations, including the control's implementation, but accountability for the *risk itself* lies with the risk owner.

CSystem owner

A system owner is responsible for a specific system, and may operate controls within that system, but the accountability for the broader risk associated with a scenario falls to the risk owner.

DData custodian

A data custodian is responsible for the care and management of data, which is distinct from the overall accountability for managing a risk scenario.

Concept tested: Risk ownership and accountability

Topics

#Risk owner responsibilities#Accountability in risk management#Risk response#Control ownership

Community Discussion

No community discussion yet for this question.

Full CRISC Practice