CRISC - Governance (26% of the exam) - Section 1.2

Define organisational structures, roles and responsibilities that support effective risk governance.

Define organisational structures, roles and responsibilities using tools such as a RACI matrix to assign accountability for IT risk. Distinguish between board oversight at the governance level and operational risk ownership at the execution level.

Roles and responsibilitiesRACIBoard oversightAccountability

Practice question for this objective

Free sampleGovernancehard

An enterprise has documented a repeatable process to identify, assess and treat IT risk, yet a maturity review finds no board oversight of risk, no defined appetite and no tone-from-the-top on acceptable behaviour. Mapping the gap against the components of an enterprise risk management framework, which component is most clearly absent?

  • AThe information, communication and reporting component that moves risk data between the relevant layers of the organisation
  • BThe governance and culture component covering board oversight, defined appetite and the desired tone for risk behaviour Correct
  • CThe review and revision component that monitors performance and refreshes the approach as the enterprise changes over time
  • DThe performance component covering identification, assessment, prioritisation and the implementation of risk responses
Board oversight, risk appetite and behavioural tone belong to the governance and culture component of an ERM framework, distinct from the risk process itself. An ERM framework separates the governance and culture that direct the programme from the performance activities that run the process; oversight, appetite and tone are governance and culture elements, so their absence points to that component being missing even when the assessment and treatment process operates well.

Why A is wrong: Reporting flows do matter, but the review describes missing oversight and tone rather than broken information flows, so this component is not the primary gap being identified here.

Why B is correct: Board oversight, risk appetite and tone-from-the-top all sit within the governance and culture component, which is precisely what the review found absent despite a working risk process.

Why C is wrong: Review and revision keeps the framework current, yet the deficiency described is the lack of governing oversight and appetite, not the absence of periodic refresh of an existing approach.

Why D is wrong: Performance activities are exactly what the enterprise already has through its repeatable process, so this component is present rather than the one that the maturity review found missing.

See more CRISC practice questions, answers explained.

Exam traps in Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • The chief risk officer reports to the chief information officer, who already coordinates the technology controls being assessed.

    Why it is wrong: This places the risk function under the very executive whose technology activities it must challenge, which undermines independence rather than preserving it.

  • Set by each IT operations team, then aggregated upward into a single board-level appetite statement

    Why it is wrong: Bottom-up aggregation looks participative, but appetite is a strategic boundary the board owns; deriving it from operational preferences inverts the governance direction COSO ERM defines.

  • The board sets risk appetite and oversees the risk programme, while management designs and operates the day-to-day controls

    Why it is wrong: This is close and tempting, but the board approves rather than unilaterally sets appetite on its own, and the wording understates management ownership of the risk itself.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.