CRISC - Governance - Section 1.10

Maintain an enterprise risk profile and apply professional ethics in the conduct of risk management.

Maintain an enterprise risk profile by aggregating individual risk exposures into a consolidated view that supports prioritisation and reporting. Apply the ISACA Code of Professional Ethics to guide conduct when risk management findings conflict with organisational or personal interests.

Risk profileProfessional ethicsISACA Code of Professional EthicsRisk aggregation

Practice question for this objective

Free sampleGovernancemedium

A board receives a flat list of more than two hundred individual IT risk entries each month and complains it still cannot see where the organisation stands overall. A risk practitioner is asked to convert this into an enterprise risk profile that supports governance decisions. Which characteristic most distinguishes a useful enterprise risk profile from the existing list?

  • AIt presents the organisation's most significant aggregated exposures ranked against appetite, giving the board a prioritised enterprise-level view for decisions. Correct
  • BIt records every identified risk in full technical detail so that no individual exposure is ever omitted from the board's monthly pack.
  • CIt assigns a named technical owner and a remediation due date to each of the individual control weaknesses on the register.
  • DIt converts every qualitative rating into a single monetary loss figure so the entries can be summed into one total exposure number.
Understand that an enterprise risk profile is a prioritised, aggregated view of the most significant risks against appetite, not an exhaustive register of every entry. An enterprise risk profile aggregates and prioritises the organisation's most significant risks and presents them against risk appetite so governance bodies can see the overall position and decide where to act. This is distinct from a risk register, which captures granular detail, owners and treatment status; the profile exists to summarise and steer, which is why a prioritised view against appetite, rather than fuller detail or a single summed number, is its defining feature.

Why A is correct: A profile is the prioritised, aggregated portrayal of the most significant risks measured against appetite, which is exactly the enterprise-level view the board needs to govern, so this is correct.

Why B is wrong: Exhaustive detail sounds thorough, but reproducing every entry recreates the unusable list; a profile deliberately summarises and prioritises rather than capturing all exposures in full.

Why C is wrong: Owners and due dates matter for operational tracking, but these belong to the register and treatment plans; adding them does not give the board the consolidated position a profile provides.

Why D is wrong: A monetary total seems decision-useful, but forcing all risks into one summed figure misrepresents diverse and correlated exposures and is not what defines a risk profile.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Governance objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.