Certified in Risk and Information Systems Control (CRISC) — Question 756
Which of the following would MOST likely result in updates to an IT risk profile?
Answer options
- A. Changes in senior management.
- B. Establishment of a risk committee.
- C. External audit findings.
- D. Feedback from focus groups.
Correct answer: C
Explanation
External audit findings are crucial as they provide an independent assessment of the organization's risk management processes, potentially highlighting areas needing improvement. In contrast, changes in senior management, establishment of a risk committee, and feedback from focus groups may influence risk management but are less likely to lead to immediate updates in the risk profile.