CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium

A financial institution is implementing a new customer relationship management (CRM) system. To ensure data privacy and regulatory compliance, the project team is documenting all data flows, access permissions, and encryption standards for sensitive customer information within the new system. This documentation will be regularly reviewed and updated. Which of the following is the primary purpose of this control documentation?

  1. ATo facilitate incident response planning for data breaches.
  2. BTo train new employees on system usage and data entry.
  3. CTo provide evidence for external audits and regulatory inspections.
  4. DTo enable effective control monitoring and maintenance.
Show answer & explanation

Correct answer: D. To enable effective control monitoring and maintenance.

Comprehensive control documentation, including data flows and access permissions, is essential for effective control monitoring and maintenance. It provides the baseline against which controls can be assessed for their ongoing effectiveness and ensures they are updated as needed.

Why the other options are wrong

  • A. Documentation can assist incident response, but its primary role is not solely focused on breach planning.
  • B. Training is a separate activity, though documentation can be a resource for it.
  • C. While a benefit, providing evidence for audits is a secondary purpose, not the primary operational driver.

Control Documentation Purpose

The primary role of control documentation is to provide a clear, detailed record of controls for effective monitoring, maintenance, and assurance.

  • Essential for understanding how controls are designed and operate.
  • Facilitates control monitoring and testing.
  • Supports compliance, audits, and continuous improvement.

Memory trick: Document controls to KEEP them working.

More Risk Response and Reporting questions