CRISC - Governance - Section 1.2

Define organisational structures, roles and responsibilities that support effective risk governance.

Define organisational structures, roles and responsibilities using tools such as a RACI matrix to assign accountability for IT risk. Distinguish between board oversight at the governance level and operational risk ownership at the execution level.

Roles and responsibilitiesRACIBoard oversightAccountability

Practice question for this objective

Free sampleGovernancehard

An enterprise has documented a repeatable process to identify, assess and treat IT risk, yet a maturity review finds no board oversight of risk, no defined appetite and no tone-from-the-top on acceptable behaviour. Mapping the gap against the components of an enterprise risk management framework, which component is most clearly absent?

  • AThe information, communication and reporting component that moves risk data between the relevant layers of the organisation
  • BThe governance and culture component covering board oversight, defined appetite and the desired tone for risk behaviour Correct
  • CThe review and revision component that monitors performance and refreshes the approach as the enterprise changes over time
  • DThe performance component covering identification, assessment, prioritisation and the implementation of risk responses
Board oversight, risk appetite and behavioural tone belong to the governance and culture component of an ERM framework, distinct from the risk process itself. An ERM framework separates the governance and culture that direct the programme from the performance activities that run the process; oversight, appetite and tone are governance and culture elements, so their absence points to that component being missing even when the assessment and treatment process operates well.

Why A is wrong: Reporting flows do matter, but the review describes missing oversight and tone rather than broken information flows, so this component is not the primary gap being identified here.

Why B is correct: Board oversight, risk appetite and tone-from-the-top all sit within the governance and culture component, which is precisely what the review found absent despite a working risk process.

Why C is wrong: Review and revision keeps the framework current, yet the deficiency described is the lack of governing oversight and appetite, not the absence of periodic refresh of an existing approach.

Why D is wrong: Performance activities are exactly what the enterprise already has through its repeatable process, so this component is present rather than the one that the maturity review found missing.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Governance objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.