Certified in Risk and Information Systems Control (CRISC) — Question 382

Which of the following is the PRIMARY reason to adopt key control indicators (KCIs) in the risk monitoring and reporting process?

Answer options

Correct answer: D

Explanation

The correct answer, D, highlights that KCIs are primarily used to assess how effective risk mitigation measures are. Options A, B, and C, while relevant to risk management, do not focus specifically on the effectiveness of mitigation, which is the key aspect of KCIs.