CRISC - Risk Response and Reporting (32% of the exam) - Section 3.10

Report risk and control status to stakeholders using metrics such as KPIs, KRIs and KCIs and appropriate visualisations.

Report risk and control status to stakeholders using key risk indicators (KRIs), key performance indicators (KPIs), and key control indicators (KCIs) presented in appropriate visualisations such as heat maps and dashboards. Design each metric to be actionable, distinguishing lagging indicators that confirm past outcomes from leading indicators that signal emerging risk.

Key risk indicatorsKey performance indicatorsKey control indicatorsRisk reporting

Practice question for this objective

Free sampleRisk Response and Reportinghard

A risk committee complains that a key risk indicator never moves until a loss has already happened, giving them no time to act. Which property must the redesigned indicator have to fix this?

  • AIt should be derived from confirmed incident records so that every reported value is fully auditable
  • BIt should report the cumulative financial losses already suffered over the past four quarters
  • CIt should be reported far more frequently so any change is visible to the committee sooner
  • DIt should track a condition that tends to change before the risk materialises, giving advance warning Correct
A useful key risk indicator is leading: it tracks a precursor that changes before the risk materialises, giving stakeholders time to act. Leading indicators measure conditions that precede loss events, so the value shifts while there is still time to respond; basing an indicator on incidents or accumulated losses, even reported frequently, only confirms exposure after it has already occurred.

Why A is wrong: Confirmed incidents are accurate but lagging, so basing the indicator on them keeps it backward-looking and reproduces the exact timing problem the committee raised.

Why B is wrong: Cumulative losses summarise outcomes that have already occurred, so this remains a lagging view and offers no earlier signal than the current indicator does.

Why C is wrong: Higher reporting frequency speeds delivery but a lagging metric still only moves after the event, so refreshing it more often cannot create the advance warning the committee needs.

Why D is correct: An effective key risk indicator is leading, measuring a precursor that shifts ahead of the loss event, which is what gives the committee time to respond before exposure crystallises.

See more CRISC practice questions, answers explained.

Exam traps in Risk Response and Reporting

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • The number of privileged accounts that exist across the production estate at month end

    Why it is wrong: This counts the population the control governs, not whether the control runs, so it describes scope rather than control performance and would not reveal a control that has stopped operating.

  • The KRI data is unreliable and should be suspended until the control indicator turns amber on the next reporting cycle

    Why it is wrong: Assuming the KRI is wrong because it disagrees with the KCI is tempting but premature, since the divergence more likely exposes a real control or threshold problem to investigate.

  • A key performance indicator that reports the percentage of service availability achieved against the agreed target

    Why it is wrong: A KPI measures how well a process is performing against its objective, so it confirms achieved performance rather than signalling an emerging rise in exposure ahead of a loss.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.