Certified in Risk and Information Systems Control (CRISC) — Question 1061
Which of the following are the common mistakes while implementing KRIs?
Each correct answer represents a complete solution. (Choose three.)
Answer options
- A. Choosing KRIs that are difficult to measure
- B. Choosing KRIs that has high correlation with the risk
- C. Choosing KRIs that are incomplete or inaccurate due to unclear specifications
- D. Choosing KRIs that are not linked to specific risk
Correct answer: A, C, D
Explanation
The correct answers A, C, and D highlight key pitfalls such as measuring KRIs that are challenging to quantify, using incomplete or inaccurate KRIs due to poor specifications, and failing to connect KRIs to specific risks. Option B is incorrect because choosing KRIs with high correlation to risk is actually a best practice, not a mistake.