
Certified in Risk and Information Systems Control
Domain 1Objective 2
Risk Management CRISC Practice Questions (Page 5)
Part of the Domain 1: Governance domain, which accounts for 26% of the CRISC exam.
26questions here
6free pages
6concepts
26%of the exam
Questions 21–25
- 21
A financial institution is implementing the three lines of defense model. The first line (business units) has been given responsibility for identifying and managing risks in their operations. The second line (risk management) is responsible for monitoring and challenging the first line's risk activities. The third line (internal audit) provides independent assurance. However, the internal audit function has been asked to help the first line design and implement new controls for a critical process. What is the most appropriate response from internal audit?
Select an answer first - 22
A public sector organization is required to implement a risk management framework that emphasizes internal control and is widely used for compliance with financial reporting regulations. The organization's leadership wants a framework that integrates risk management with internal control and can be used to evaluate the effectiveness of internal controls. Which framework is most appropriate?
Select an answer first - 23
In a large bank, the compliance function is responsible for monitoring adherence to regulatory requirements and providing guidance to business units on compliance risks. According to the three lines of defense model, which line of defense does the compliance function represent?
Select an answer first - 24
A multinational corporation is implementing an ERM program. The board has approved a risk appetite that is aggressive for market expansion but conservative for operational risk. The risk team is tasked with developing a risk profile that aligns with this appetite. During the process, they discover that the organization's current risk exposure in operational areas is higher than the conservative tolerance. The board is unwilling to change its risk appetite. What is the most appropriate course of action for the risk team?
Select an answer first - 25
A technology company is preparing its risk profile for the board. The company has a high risk appetite for innovation, but a low tolerance for data breaches. The risk team has identified that the company's current risk exposure for data breaches is within the low tolerance. However, the company is planning to launch a new product that will significantly increase the amount of customer data it processes. What should the risk team do when developing the risk profile?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.