A risk practitioner is establishing how legal, regulatory and contractual requirements should feed into the IT risk programme. Which approach BEST ensures these external obligations are reliably reflected in the risk register?
- AAsk the legal department to review the risk register once a year and flag any obligations that appear to have been missed by the risk team.
- BRequire each business unit to self-certify quarterly that it complies with all laws applicable to its activities and store the certificates centrally.
- CSubscribe to a regulatory news feed and circulate relevant alerts to the risk team so they can decide whether each item warrants any further action.
- DMaintain a compliance obligations register that maps each legal, regulatory and contractual requirement to the relevant risk scenarios and controls, and review it on change. Correct
Why A is wrong: An annual legal review is a useful check, but a once-a-year backstop reacts to gaps rather than preventing them and will miss obligations that change mid-cycle.
Why B is wrong: Self-certification of compliance records an assertion but does not connect specific obligations to risk scenarios or controls, so the register stays incomplete.
Why C is wrong: A news feed raises awareness of change but leaves the linkage to scenarios and controls undefined, so obligations are not systematically captured in the register.
Why D is correct: Mapping each obligation to scenarios and controls and updating it when laws or contracts change keeps the IT risk register continuously aligned with external requirements.