CISA - Governance and Management of IT - Section 2.1

Assess IT policies, standards and procedures, enterprise architecture and enterprise risk management practices.

Recognise how IT policies, standards and procedures provide a control framework, and how enterprise architecture documents the relationships between business processes and IT components. Assess enterprise risk management practices to determine whether risk identification, analysis and response are adequate.

IT policies and standardsprocedures and practicesenterprise architectureenterprise risk management

Practice question for this objective

Free sampleGovernance and Management of ITmedium

An IS auditor is reviewing the enterprise risk management programme. Which statement BEST describes the relationship between inherent risk, residual risk and risk appetite?

  • AInherent risk is the worst case loss, residual risk is the most likely loss, and risk appetite is the average loss the organisation expects to absorb each year.
  • BInherent risk is the risk before controls, residual risk is the risk after controls, and risk appetite is the maximum residual risk the board is willing to accept. Correct
  • CInherent risk is the risk measured by the second line of defence, residual risk is measured by internal audit, and risk appetite is set jointly by both functions.
  • DInherent risk is the risk recorded in the risk register, residual risk is the risk discussed in the audit report, and risk appetite is the tolerance for missed control tests.
State precisely what inherent risk, residual risk and risk appetite mean so that enterprise risk reporting can be evaluated against governance thresholds. ISO 31000 and CISA reference material both treat inherent risk as the pre-control exposure, residual risk as what remains after controls operate, and risk appetite as the bounded amount of residual risk the board accepts in pursuit of objectives.

Why A is wrong: This frames the concepts as expected loss statistics rather than as control-related and governance constructs, so it confuses risk quantification with risk classification.

Why B is correct: This matches the standard definitions used by ISO 31000 and the COSO framework, in which appetite sets the ceiling against which residual exposure is compared by governance.

Why C is wrong: Risk appetite is owned by the board and senior management, not jointly with internal audit, and the assignment of measurement to lines of defence is not how the concepts are defined.

Why D is wrong: This option ties the definitions to artefacts rather than to the substantive meaning of each concept, so it would mislead an auditor assessing the maturity of the programme.

See more CISA practice questions, answers explained.

More in this domain

Back to all Governance and Management of IT objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.