CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityHard

A project manager is overseeing the implementation of a new enterprise resource planning (ERP) system. During the planning phase, a key stakeholder expresses concern that the project might not deliver the expected business benefits due to insufficient user adoption. Which of the following risk categories does this concern PRIMARILY fall under?

  1. AStrategic risk
  2. BCompliance risk
  3. COperational risk
  4. DTechnical risk
Show answer & explanation

Correct answer: A. Strategic risk

Insufficient user adoption directly impacts whether the ERP system achieves its intended strategic goals (e.g., improved efficiency, better decision-making). If users don't adopt it, the project fails to deliver on its strategic objectives, thus making it a strategic risk.

Why the other options are wrong

  • B. Compliance risks relate to violations of laws, regulations, or internal policies.
  • C. Operational risks relate to day-to-day operations and processes (e.g., process failures, human error).
  • D. Technical risks relate to the technology itself (e.g., software bugs, integration issues).

Strategic Risk

Risks that affect an organization's ability to achieve its long-term objectives and overall strategy, often stemming from poor business decisions, market changes, or failure to execute strategy.

  • Impacts organizational goals and competitive advantage.
  • Often involves external factors or major internal decisions.
  • Can lead to significant financial or reputational loss.

Memory trick: Strategic for goals, Operational for daily, Financial for money, Compliance for rules.

More Information Technology and Security questions