TechNuggets Academy

Governance

Free Certified in Risk and Information Systems Control practice — 6 questions on Governance, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 1: Governance
A large regional bank's risk management function (second line of defense) has been directly executing key control activities — such as approving loan exceptions and running reconciliation checks — on behalf of understaffed first-line business units. Internal audit (third line) flags this arrangement during its annual review. What is the BEST governance response?
In the three lines model, the first line owns and executes risk and controls as part of daily operations; the second line's role is to establish frameworks, monitor, and advise — not to perform first-line control activities. Restoring this separation preserves the independence the model is built on and lets the second line objectively evaluate the very controls it would otherwise be running.
Question 2 of 6 · Domain 1: Governance
A board approves a risk appetite statement permitting up to $50M in annual loss exposure from emerging-market expansion. The enterprise's risk capacity assessment, based on available capital reserves, shows the organization can only absorb a maximum of $30M in losses before solvency is threatened. What should the risk practitioner recommend?
Risk appetite must never be set above risk capacity, since capacity represents the objective, absolute maximum loss the enterprise can sustain and survive. When appetite exceeds capacity, the governance failure must be corrected at its source — the appetite statement — not masked with downstream fixes.
Question 3 of 6 · Domain 1: Governance
According to ISACA risk governance guidance, which party holds ultimate accountability for setting and formally approving the organization's risk appetite?
The board (or equivalent governing body) is ultimately accountable for enterprise risk governance, including formal approval of the risk appetite statement, even though the CRO and second-line functions do the analytical and operational work that informs it.
Question 4 of 6 · Domain 1: Governance
An organization defines KRI thresholds where a shift from 'green' to 'yellow' status triggers escalation to the risk committee, and a shift from 'yellow' to 'red' triggers immediate board notification. This threshold-setting approach primarily operationalizes which governance element?
Risk tolerance is the acceptable level of variation around risk appetite for a specific risk or metric, and it is typically expressed through measurable thresholds like KRI bands that trigger escalation actions when breached — exactly what this scenario describes.
Question 5 of 6 · Domain 1: Governance
A client contract obligates a company to retain certain customer data for seven years. A newly enacted data privacy regulation in the company's operating jurisdiction requires deletion of that same data category after five years. What is the BEST course of action?
Legal and regulatory requirements generally take precedence over contractual obligations; a contract term that conflicts with mandatory law is typically unenforceable to the extent of the conflict. The organization must comply with the regulatory deletion mandate and work to renegotiate or amend the contract to resolve the conflict going forward.
Question 6 of 6 · Domain 1: Governance
Under the ISACA Code of Professional Ethics applicable to CRISC holders, which of the following situations represents an actual conflict of interest requiring disclosure?
A close personal financial interest — such as a spouse's significant equity stake in a vendor under the practitioner's own evaluation — creates a real potential for biased judgment and must be disclosed under professional ethics obligations, regardless of whether actual bias occurs.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →