Certified in Risk and Information Systems Control (CRISC) — Question 1139
Which of the following is the ULTIMATE objective of utilizing key control indicators (KCIs) in the risk management process?
Answer options
- A. To provide benchmarks for assessing control design effectiveness against industry peers
- B. To provide insight into the effectiveness of the internal control environment
- C. To provide early warning signs of a potential change in risk level
- D. To provide a basis for determining the criticality of risk mitigation controls
Correct answer: B
Explanation
The correct answer, B, highlights that the primary purpose of KCIs is to evaluate how effective the internal control environment is. Option A focuses on comparing with industry peers, which is less about internal effectiveness. Option C emphasizes early warning signs, which is important but not the ultimate objective. Option D pertains to assessing the importance of controls, which is a secondary focus rather than the main goal.