ISACA CRISC — Certified in Risk and Information Systems Control · Domain 1 · 26% of exam

Governance

Drill 20 practice questions focused entirely on Governance for the ISACA CRISC exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

A mid-sized financial services firm has just acquired a smaller fintech company that operated with an informal, spreadsheet-based approach to risk tracking. The acquiring firm uses a mature enterprise risk management (ERM) program aligned to a formal framework. The board wants the acquired entity's risks reflected in enterprise reporting within one quarter. As the risk practitioner leading integration, what should be your FIRST priority?

Reviewed for accuracy · Report an issue
Question 2 of 20

A manufacturing company recently redesigned its procurement process to speed up vendor onboarding, allowing purchasing managers to approve new suppliers within hours. Six months later, the risk practitioner notices that several onboarded vendors were never screened for sanctions-list or conflict-of-interest issues, though the corporate policy still requires such screening. What is the MOST significant governance concern the risk practitioner should raise?

Reviewed for accuracy · Report an issue
Question 3 of 20

A newly appointed CRISC-certified risk practitioner reviews the enterprise risk register and finds that many identified risks are documented in technical terms with no reference to how they could affect the organization's stated growth and market-expansion strategy. Senior management complains that risk reports are not useful for decision-making. What should the practitioner do FIRST to address this concern?

Reviewed for accuracy · Report an issue
Question 4 of 20

A newly appointed CRISC-certified risk practitioner reviews the information security department's annual goals. The goals emphasize maximizing the number of vulnerabilities patched and increasing firewall rule counts, but make no reference to the enterprise's stated strategic objective of expanding into new digital markets. Which action should the practitioner recommend FIRST to improve governance?

Reviewed for accuracy · Report an issue
Question 5 of 20

A newly appointed CRISC-certified risk manager discovers that the enterprise has a formally approved code of conduct, but employees routinely bypass its requirements around gift acceptance from vendors, and no disciplinary action has ever been taken. Senior leadership acknowledges the code exists but treats it as guidance rather than a binding rule. Which action should the risk manager recommend FIRST to strengthen the organization's risk governance?

Reviewed for accuracy · Report an issue
Question 6 of 20

A manufacturing company has automated a previously manual invoice-approval business process, introducing a workflow tool that routes approvals electronically. Three months later, an internal audit finds employees are still following the outdated documented standard that references manual sign-offs, creating confusion about who is accountable for approvals. As the risk practitioner, what should you recommend as the MOST appropriate first action to address the governance gap?

Reviewed for accuracy · Report an issue
Question 7 of 20

A multinational retailer processes customer data across several countries. The risk practitioner discovers that a new data-localization law in one country directly conflicts with a data-sharing clause in a signed contract with a global cloud provider, and that the marketing department has continued cross-border transfers to meet campaign deadlines. What should the risk practitioner do FIRST?

Reviewed for accuracy · Report an issue
Question 8 of 20

A financial services firm outsources its customer data processing to a third-party cloud provider. The contract includes a service-level agreement (SLA) requiring 99.9% availability and specific data-breach notification timelines mandated by the firm's regulator. During a governance review, the risk manager notes that no internal party has been formally assigned to monitor the provider's adherence to these contractual and regulatory obligations. Which action should the risk manager recommend FIRST?

Reviewed for accuracy · Report an issue
Question 9 of 20

A newly appointed CRO discovers that while the enterprise has a documented risk management framework, business unit managers routinely treat risk activities as the sole responsibility of the risk function. Incidents are frequently escalated late because managers do not see risk identification as part of their day-to-day duties. The CRO wants a sustainable governance change to correct this behavior. Which action would MOST effectively address the root cause?

Reviewed for accuracy · Report an issue
Question 10 of 20

A newly appointed chief risk officer at a mid-sized insurer discovers that risk activities are performed inconsistently across departments, with each unit using its own spreadsheets, terminology, and rating scales. The board asks the CRO to recommend the single most important first step to establish effective enterprise risk management. Which recommendation best addresses the board's request?

Reviewed for accuracy · Report an issue
Question 11 of 20

A manufacturing company is formalizing its three lines of defense model. During implementation, the head of production operations argues that because the risk management function performs quarterly risk assessments of the production floor, that function should be accountable for ensuring production-line safety controls operate effectively day-to-day. How should the risk practitioner respond to correctly assign responsibility under the three lines of defense model?

Reviewed for accuracy · Report an issue
Question 12 of 20

A newly appointed CRO discovers that risk-related decisions at a manufacturing company are frequently delayed and sometimes reversed. Investigation reveals that both the IT steering committee and the operational risk committee believe they hold final authority over technology risk acceptance, while business unit heads independently accept residual risks without informing either committee. Which action should the CRO prioritize FIRST to address the root cause?

Reviewed for accuracy · Report an issue
Question 13 of 20

A multinational manufacturer operates through highly autonomous regional business units, each with its own management team that makes independent risk decisions. Senior leadership has become concerned that similar risks are being treated very differently across regions, leading to inconsistent controls and unclear enterprise-wide accountability. Which change to the organizational structure would BEST address this concern while preserving regional operational flexibility?

Reviewed for accuracy · Report an issue
Question 14 of 20

A newly hired risk analyst is reviewing the enterprise's document library and notices that a departmental password procedure requires a minimum of 8 characters, while the corporate information security standard mandates a minimum of 14 characters. Both documents are current and approved. Which action should the risk practitioner recommend FIRST?

Reviewed for accuracy · Report an issue
Question 15 of 20

A financial services firm operates in several countries, each with evolving data protection and reporting regulations. Over the past year, two business units were fined because they continued using outdated processes after a regulation changed, unaware that the requirement had been updated. The CRO wants to prevent recurrence by establishing a governance mechanism. Which approach BEST addresses the underlying governance weakness?

Reviewed for accuracy · Report an issue
Question 16 of 20

A financial services firm recently paid a substantial regulatory fine after failing to report suspicious transactions within mandated timeframes. In response, the board directs the risk function to review the enterprise's stated tolerance for compliance-related process failures. Which action best reflects a sound governance approach to setting the revised risk tolerance?

Reviewed for accuracy · Report an issue
Question 17 of 20

A newly appointed CRO finds that the enterprise has a board-approved risk appetite statement, but individual business units continue to make risk decisions based on their own informal thresholds. As a result, one aggressive business unit is accepting risks that exceed enterprise-level limits, while a conservative unit is rejecting profitable opportunities well within acceptable bounds. Which action would MOST effectively address the root cause of this inconsistency?

Reviewed for accuracy · Report an issue
Question 18 of 20

A financial services company's board has approved a formal statement declaring that the enterprise will accept minimal risk to customer data confidentiality but is willing to pursue moderate operational risk to enable rapid product innovation. During a project review, a risk practitioner finds a proposed feature that would expose customer personal data to a level exceeding the defined threshold, though it stays within the enterprise's overall ability to absorb a loss without threatening solvency. What is the practitioner's BEST course of action?

Reviewed for accuracy · Report an issue
Question 19 of 20

A retail bank's board has set a risk appetite statement that limits acceptable operational losses to a low level relative to net revenue. Management defines a tolerance threshold allowing monthly fraud losses to fluctuate up to 15% above the target before escalation is required. In one month, fraud losses spike to 12% above target due to a seasonal promotion, then return to normal the following month. The CRO is deciding how to respond. What is the MOST appropriate action?

Reviewed for accuracy · Report an issue
Question 20 of 20

A manufacturing company's board wants to enter a new overseas market that requires significant upfront investment in unfamiliar regulatory environments. The CRO notes that while the enterprise's stated risk appetite would comfortably permit the venture, the company's current cash reserves, insurance coverage, and available skilled compliance staff are already heavily committed to existing operations. Which concept should the CRO emphasize to the board to most accurately frame the concern about this expansion?

Reviewed for accuracy · Report an issue

More CRISC practice

Keep going with the other ISACA CRISC — Certified in Risk and Information Systems Control domains, or take a full timed mock exam.

← Back to CRISC overview