Certified in Risk and Information Systems Control (CRISC) — Question 854
A new risk practitioner finds that decisions for implementing risk response plans are not being made. Which of the following would MOST likely explain this situation?
Answer options
- A. The organization's risk awareness program is ineffective.
- B. The organization has a high level of risk appetite.
- C. Risk ownership is not being assigned properly.
- D. Risk management procedures are outdated.
Correct answer: C
Explanation
The correct answer is C because without proper assignment of risk ownership, individuals may not take responsibility for managing risks, leading to indecision. Option A could contribute to the problem but does not directly address ownership. Option B suggests a willingness to take risks, which doesn't relate to decision-making issues, while option D implies outdated procedures, which may hinder action but does not specifically indicate ownership failure.