CRISC - Governance (26% of the exam) - Section 1.1

Align the IT risk management approach with the organisation's strategy, goals and objectives.

Describe how IT risk management supports organisational strategy, business objectives, and value delivery. Recognise that misalignment between IT risk priorities and strategic direction undermines investment decisions and governance credibility.

Organisational strategyBusiness objectivesStrategic alignmentValue delivery

Practice question for this objective

Free sampleGovernancemedium

A risk practitioner is asked to demonstrate that the IT risk management approach supports the organisation's strategy. Which action provides the strongest evidence of strategic alignment?

  • ADeriving risk appetite, tolerance and treatment priorities directly from the approved strategic objectives Correct
  • BMapping each identified IT risk scenario to the specific business objectives it could impair
  • CCounting how many IT risk scenarios were closed within the agreed remediation window
  • DPublishing the IT risk register to every department head on a fixed monthly schedule
Strategic alignment is proven when risk appetite, tolerance and treatment priorities are derived from approved strategic objectives. Alignment means the strategy drives the risk decisions, so deriving appetite, tolerance and treatment priorities from the approved objectives makes business intent the controlling input rather than an afterthought layered onto technical activity.

Why A is correct: When appetite, tolerance and priorities flow from the approved strategic objectives, the risk approach is demonstrably governed by strategy rather than run as an isolated technical exercise.

Why B is wrong: Mapping risks to objectives is useful and tempting because it shows traceability, but it documents exposure rather than proving the overall approach is steered by strategy.

Why C is wrong: Closure rates measure operational efficiency of treatment, so they look like progress, yet they say nothing about whether the work served the organisation's strategic goals.

Why D is wrong: Wide distribution improves transparency and feels like good governance, but circulating a register does not show that risk decisions are anchored to business strategy.

See more CRISC practice questions, answers explained.

Exam traps in Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • Recommend the treatment regardless of timing because reducing exposure is the priority

    Why it is wrong: Treating exposure as paramount sounds disciplined, but ignoring the strategic impact lets the risk function override the business objectives it is meant to serve.

  • Add more granular detail on each control failure so technical owners can see precisely what went wrong

    Why it is wrong: Deeper technical detail helps owners fix issues and looks thorough, but it pushes the report further from the strategic view management is asking for.

  • Governance and management are treated as a single combined responsibility so that the board can approve configurations and oversee strategy together

    Why it is wrong: Merging the two roles seems to simplify decision making, but COBIT deliberately separates governance from management, and combining them is the very confusion causing the board to lose oversight time.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.