Certified in Risk and Information Systems Control (CRISC) — Question 32

A global organization is considering the acquisition of a competitor. Senior management has requested a review of the overall risk profile from the targeted organization.
Which of the following components of this review would provide the MOST useful information?

Answer options

Correct answer: C

Explanation

The Risk register contains a comprehensive list of identified risks, their potential impact, and the responses planned, making it the most informative component for understanding the risk profile of the targeted organization. In contrast, the Risk appetite statement outlines the level of risk the organization is willing to take, Risk management policies provide guidelines for risk handling, and the Enterprise risk management framework describes the overall structure for managing risks, but none offer the specific insights that the Risk register does.