A board receives a flat list of more than two hundred individual IT risk entries each month and complains it still cannot see where the organisation stands overall. A risk practitioner is asked to convert this into an enterprise risk profile that supports governance decisions. Which characteristic most distinguishes a useful enterprise risk profile from the existing list?
- AIt presents the organisation's most significant aggregated exposures ranked against appetite, giving the board a prioritised enterprise-level view for decisions. Correct
- BIt records every identified risk in full technical detail so that no individual exposure is ever omitted from the board's monthly pack.
- CIt assigns a named technical owner and a remediation due date to each of the individual control weaknesses on the register.
- DIt converts every qualitative rating into a single monetary loss figure so the entries can be summed into one total exposure number.
Why A is correct: A profile is the prioritised, aggregated portrayal of the most significant risks measured against appetite, which is exactly the enterprise-level view the board needs to govern, so this is correct.
Why B is wrong: Exhaustive detail sounds thorough, but reproducing every entry recreates the unusable list; a profile deliberately summarises and prioritises rather than capturing all exposures in full.
Why C is wrong: Owners and due dates matter for operational tracking, but these belong to the register and treatment plans; adding them does not give the board the consolidated position a profile provides.
Why D is wrong: A monetary total seems decision-useful, but forcing all risks into one summed figure misrepresents diverse and correlated exposures and is not what defines a risk profile.