CRISC Certified in Risk and Information Systems ControlGovernanceEasy

A financial services company processes a vast amount of sensitive customer data. A recent internal audit revealed inconsistencies in how different departments handle data access requests and incident reporting. This has led to potential compliance gaps and increased operational risk. Which of the following governance elements is MOST likely deficient?

  1. AOrganizational risk culture.
  2. BEnterprise risk management (ERM) framework.
  3. CRisk appetite statement.
  4. DPolicies, standards, and procedures.
Show answer & explanation

Correct answer: D. Policies, standards, and procedures.

Inconsistencies in handling specific operational tasks like data access and incident reporting directly point to a lack of clear, consistent, and enforced policies, standards, and procedures.

Why the other options are wrong

  • A. While risk culture is important, the specific issue of 'inconsistencies in handling' suggests a lack of clear rules and processes, rather than a fundamental lack of risk awareness or attitude.
  • B. While ERM provides the overarching structure, the specific problem points to a deficiency in the detailed operational guidance that policies, standards, and procedures provide.
  • C. A risk appetite statement defines the level of risk an organization is willing to take, but doesn't dictate specific operational handling.

Policies, Standards, and Procedures (PSPs)

A hierarchical set of documented guidelines that define an organization's rules, mandatory requirements, and detailed steps for performing specific tasks to ensure consistency, compliance, and effective risk management.

  • Policies: High-level statements of intent.
  • Standards: Mandatory requirements for implementing policies.
  • Procedures: Detailed, step-by-step instructions for tasks.

Memory trick: Without clear PSPs, operations become a chaotic choose-your-own-adventure.

More Governance questions