CRISC Risk Monitoring, Reporting, and KRIs 1 — Questions and Answers
Question 1: A Key Risk Indicator (KRI) is BEST defined as:
- A metric that signals increasing risk exposure before an incident occurs (Correct answer)
- A measure of the financial impact of a past risk event
- A tool for identifying new risks in the environment
- A benchmark comparing organizational risk to industry peers
Correct answer: A metric that signals increasing risk exposure before an incident occurs
KRIs are forward-looking metrics that provide early warning signals of increasing risk, enabling proactive management before losses occur.
Question 2: Which characteristic distinguishes a HIGH-QUALITY KRI from a poorly designed one?
- It is measurable, timely, and directly correlated to a specific risk (Correct answer)
- It captures the largest number of risk events over time
- It is complex enough to require specialized analysis tools
- It is reported on an annual basis to maintain relevance
Correct answer: It is measurable, timely, and directly correlated to a specific risk
Effective KRIs must be quantifiable, available in time to act, and have a proven correlation to the risk they are monitoring.
Question 3: The PRIMARY purpose of risk monitoring in the CRISC framework is to:
- Detect changes in the risk environment that require updated risk responses (Correct answer)
- Identify new vulnerabilities through automated scanning
- Generate compliance reports for external regulators
- Provide technical metrics for the IT operations team
Correct answer: Detect changes in the risk environment that require updated risk responses
Risk monitoring detects environmental changes — new threats, control failures, or shifting business conditions — that may require updates to risk responses.
Question 4: Which risk reporting element is MOST valuable to a board-level audience?
- A summary of top risks and their alignment with risk appetite (Correct answer)
- Detailed technical vulnerability data from security scans
- A complete list of all identified risks in the risk register
- Raw incident counts and mean time to detection metrics
Correct answer: A summary of top risks and their alignment with risk appetite
Board members need a concise, strategic view of top risks relative to risk appetite — not granular technical details that belong in operational reporting.
Question 5: A threshold breach in a KRI should MOST immediately trigger:
- Escalation to the risk owner and review of the associated control (Correct answer)
- Immediate shutdown of the affected IT system
- An external penetration test of related systems
- An update to the annual risk assessment report
Correct answer: Escalation to the risk owner and review of the associated control
When a KRI threshold is breached, the risk owner must be notified immediately to review whether the associated controls need reinforcement or response.
Question 6: Which type of risk reporting is MOST appropriate for communicating day-to-day IT risk status to operational teams?
- Operational risk dashboards with real-time metrics (Correct answer)
- Quarterly risk committee reports
- Annual enterprise risk management report
- Board-level risk appetite summary
Correct answer: Operational risk dashboards with real-time metrics
Operational teams need real-time or near-real-time dashboards that reflect current risk status rather than periodic strategic reports.
A Key Risk Indicator (KRI) is BEST defined as: