Certified in the Governance of Enterprise IT (CGEIT) — Question 87
Which of the following would be of MOST concern regarding the effectiveness of risk management processes?
Answer options
- A. Risk management requirements are not included in performance reviews.
- B. Key risk indicators (KRIs) are not established.
- C. There is no framework to ensure effective reporting of risk events.
- D. The plans and procedures are not updated on an annual basis.
Correct answer: C
Explanation
Option C is correct because without a proper framework for reporting risk events, it becomes difficult to manage and respond to risks effectively. Options A, B, and D, while concerning, do not directly impact the immediate reporting and handling of risk events, which is critical for effective risk management.