🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control97 / 150
Question 97 of 150

A newly appointed risk manager at a mid-sized bank discovers that the enterprise risk management policy was last updated three years ago and was approved solely by the head of the IT department. The policy defines risk appetite, escalation thresholds, and the roles of business unit managers across the entire organization. The risk manager wants to correct the governance weakness. Which action should be taken FIRST?

Reviewed for accuracy · Report an issueNext question