CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentHard

An organization's risk register contains over 500 entries, many of which are outdated, duplicates, or lack sufficient detail for actionable decision-making. A CRISC professional is tasked with optimizing the risk register to make it a more effective risk management tool. Which of the following approaches should be prioritized FIRST?

  1. AConsolidate and rationalize existing risk entries to remove redundancies and improve clarity.
  2. BTrain all risk owners on the new risk scoring methodology.
  3. CIntegrate the risk register with the incident management system.
  4. DAutomate the risk register updates using a GRC tool.
Show answer & explanation

Correct answer: A. Consolidate and rationalize existing risk entries to remove redundancies and improve clarity.

Before automating, training, or integrating, the fundamental quality of the data in the risk register must be addressed. Consolidating and rationalizing existing entries ensures that the register contains accurate, unique, and actionable risks, which is a prerequisite for any subsequent optimization or utilization efforts.

Why the other options are wrong

  • B. Training on a new scoring methodology is premature if the underlying risk entries themselves are flawed.
  • C. Integration is a valuable step for enhancing risk management, but it should occur after the risk register's data quality is assured.
  • D. Automating an unoptimized, cluttered register will perpetuate existing issues, not solve them.

Risk Register Optimization

The process of refining and maintaining a risk register to ensure it is accurate, relevant, actionable, and effectively supports risk management decision-making.

  • Involves cleaning up outdated or duplicate entries.
  • Focuses on specificity and clarity of risk descriptions.
  • Ensures alignment with organizational risk appetite.

Memory trick: First, 'Clean' the register, then 'Organize' and 'Utilize' it.

More IT Risk Assessment questions