🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control92 / 150
Question 92 of 150

A newly appointed chief risk officer (CRO) finds that the enterprise risk management function operates informally, with no document defining its mandate, decision-making authority, or escalation rights. Business units frequently bypass risk reviews, claiming the risk team has no power to require them. To establish a legitimate foundation for the function, what should the CRO prioritize?

Reviewed for accuracy · Report an issueNext question