Certified in Risk and Information Systems Control (CRISC) — Question 379

Which of the following is NOT true for risk governance?

Answer options

Correct answer: B

Explanation

The correct answer is B, as risk governance does not mandate annual reporting, which is not a standard requirement. Options A, C, and D accurately describe aspects of risk governance, emphasizing its principles, objectives, and systematic approach.