An enterprise has documented a repeatable process to identify, assess and treat IT risk, yet a maturity review finds no board oversight of risk, no defined appetite and no tone-from-the-top on acceptable behaviour. Mapping the gap against the components of an enterprise risk management framework, which component is most clearly absent?
- AThe information, communication and reporting component that moves risk data between the relevant layers of the organisation
- BThe governance and culture component covering board oversight, defined appetite and the desired tone for risk behaviour Correct
- CThe review and revision component that monitors performance and refreshes the approach as the enterprise changes over time
- DThe performance component covering identification, assessment, prioritisation and the implementation of risk responses
Why A is wrong: Reporting flows do matter, but the review describes missing oversight and tone rather than broken information flows, so this component is not the primary gap being identified here.
Why B is correct: Board oversight, risk appetite and tone-from-the-top all sit within the governance and culture component, which is precisely what the review found absent despite a working risk process.
Why C is wrong: Review and revision keeps the framework current, yet the deficiency described is the lack of governing oversight and appetite, not the absence of periodic refresh of an existing approach.
Why D is wrong: Performance activities are exactly what the enterprise already has through its repeatable process, so this component is present rather than the one that the maturity review found missing.