exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 1343 discussion

Actual exam question from Isaca's CRISC
Question #: 1343
Topic #: 1
[All CRISC Questions]

A risk practitioner is reviewing accountability assignments for data risk in the risk register. Which of the following would pose the GREATEST concern?

  • A. The risk owner is a staff member rather than a department manager.
  • B. The risk owner is in a business unit and does not report through the IT department.
  • C. The risk owner is not the control owner for associated data controls.
  • D. The risk owner is listed as the department responsible for decision making.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
FredDurst
11 months, 1 week ago
Selected Answer: C
Straight from the CRISC book "a control should be owned by the owner of the risk that it mitigates. However, the control may be owned by someone else in the case of controls that affect more than one risk."
upvoted 1 times
...
mynk29
1 year, 6 months ago
Something is missing in this question. RIsk owner is a person not a department/business unit. Also risk owner should be a senior person not a staff member.. so all of the options other than C are a concern.
upvoted 1 times
...
CbtL
1 year, 7 months ago
Selected Answer: D
Have to go with D. Needs to be assigned to an individual, and control owner and risk owner do not need to be the same person.
upvoted 2 times
...
ldl
1 year, 7 months ago
Selected Answer: D
To ensure accountability, the risk owner must be an individual, not a department or organization.
upvoted 3 times
...
Broesweelies
1 year, 8 months ago
Selected Answer: A
A. The risk owner is a staff member rather than a department manager. The greatest concern would be when the risk owner is a staff member rather than a department manager. Risk owners should typically be individuals with the appropriate level of authority and decision-making power to manage and address the risks effectively. Department managers or higher-level management personnel are better positioned to allocate resources, drive risk mitigation efforts, and ensure cross-functional collaboration when needed.
upvoted 1 times
CbtL
1 year, 7 months ago
Would say D first, then A. Having a non-decision maker as the accountable person is not good, but second to not having a specific person assigned as the risk owner.
upvoted 1 times
...
...
Koulyo
1 year, 8 months ago
It is D. as per your first choice.
upvoted 2 times
...
john_boogieman
1 year, 9 months ago
Selected Answer: C
Correction, reason: When the risk owner is not the control owner for associated data controls, it can lead to a lack of coordination and accountability in managing the risk. This is because the risk owner is responsible for identifying and managing risks, while the control owner is responsible for implementing and maintaining controls to mitigate those risks. If the risk owner and control owner are not the same person, it can be difficult to ensure that the controls are appropriate and effective in mitigating the identified risks, and that there is accountability for their implementation and effectiveness. In summary, while the risk owner does not necessarily have to be the owner of the control, it is important to ensure that there is coordination and accountability between the two roles to effectively manage and mitigate risks.
upvoted 1 times
...
john_boogieman
1 year, 9 months ago
Selected Answer: D
To ensure accountability, the risk owner must be an individual, not a department or organization. On the other hand, the owner of the risk need not necessarily be the owner of the control and that it is not is not a concern.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...