CRISC - Governance - Section 1.5

Identify legal, regulatory and contractual requirements that shape the IT risk programme.

Identify the legal obligations, regulatory compliance requirements, and contractual requirements - including privacy law - that define the minimum control baseline for an IT risk programme. Recognise that failure to map these external demands into the risk register creates unmanaged compliance exposure.

Regulatory complianceLegal obligationsContractual requirementsPrivacy law

Practice question for this objective

Free sampleGovernancemedium

A risk practitioner is establishing how legal, regulatory and contractual requirements should feed into the IT risk programme. Which approach BEST ensures these external obligations are reliably reflected in the risk register?

  • AAsk the legal department to review the risk register once a year and flag any obligations that appear to have been missed by the risk team.
  • BRequire each business unit to self-certify quarterly that it complies with all laws applicable to its activities and store the certificates centrally.
  • CSubscribe to a regulatory news feed and circulate relevant alerts to the risk team so they can decide whether each item warrants any further action.
  • DMaintain a compliance obligations register that maps each legal, regulatory and contractual requirement to the relevant risk scenarios and controls, and review it on change. Correct
External obligations are reliably reflected when each requirement is mapped to risk scenarios and controls in a maintained obligations register. A compliance obligations register creates a traceable link from each law, regulation or contract clause to the scenarios and controls that address it, so coverage can be demonstrated and kept current as obligations change.

Why A is wrong: An annual legal review is a useful check, but a once-a-year backstop reacts to gaps rather than preventing them and will miss obligations that change mid-cycle.

Why B is wrong: Self-certification of compliance records an assertion but does not connect specific obligations to risk scenarios or controls, so the register stays incomplete.

Why C is wrong: A news feed raises awareness of change but leaves the linkage to scenarios and controls undefined, so obligations are not systematically captured in the register.

Why D is correct: Mapping each obligation to scenarios and controls and updating it when laws or contracts change keeps the IT risk register continuously aligned with external requirements.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Governance objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.