How to Identify Business Stakeholders for IT Risk Scenarios?

Which of the following is MOST helpful in identifying appropriate business stakeholders to construct and assess IT risk scenarios?

  1. Reviewing the organization's business RACI charts
  2. Mapping each risk event to related business processes Source Reference Answer
  3. Consulting senior management for likely business candidates
  4. Conducting risk and business impact analyses

Community Votes

B
67%
A
33%

67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests your understanding of linking IT risks to business process owners, while the common trap involves choosing administrative tools like RACI charts that assume stakeholders are already defined.

This CRISC practice question examines the most effective approach for identifying business stakeholders during IT risk scenario development, with strong community consensus supporting process-based mapping.

Option A (Reviewing RACI charts) is the most frequent distractor; while RACI matrices clarify responsibilities, they are typically utilized after stakeholders have been identified through process mapping, making them less effective for initial discovery.

Community Discussion (3 comments)

6ada4e1 👍 1 Selected: B
b es la respuesta
Abbey2 👍 1 Selected: A
In identifying appropriate business stakeholders to construct and assess IT risk scenarios, the most helpful approach is: A. Reviewing the organization's business RACI charts. RACI charts (Responsible, Accountable, Consulted, and Informed) provide a clear delineation of roles and responsibilities within an organization's processes and projects. By reviewing these charts, you can identify stakeholders who are Responsible, Accountable, or Consulted for various business processes and systems that might be affected by IT risks. This makes it easier to pinpoint the right individuals who have the necessary knowledge, authority, and interest in specific risk areas. These stakeholders are crucial in constructing and assessing IT risk scenarios as they can provide relevant insights, resources, and support. While the other options have their merits: Mapping each risk event to related business processes (option B) helps in understanding the impact of risks but might not directly identify the stakeholders.
K5000ism 👍 1 Selected: B
B. Mapping each risk event to related business processes

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Mapping risk events to related business processes directly reveals the individuals responsible for those operations. In CRISC methodology, business process owners are the primary stakeholders who must participate in constructing and assessing IT risk scenarios. This approach ensures comprehensive coverage of organizational functions and establishes clear accountability before quantitative analysis begins.

Why the Other Options Are Wrong

Reviewing RACI charts (Option A) defines roles and responsibilities but assumes stakeholders and processes are already established, making it a secondary step rather than an identification tool. Consulting senior management (Option C) lacks systematic rigor and often overlooks mid-level process owners who possess granular risk knowledge. Conducting risk and business impact analyses (Option D) focuses on quantifying likelihood and financial impact, not on determining who should be involved in the scenario-building phase.

Community Comment Notes

The voting split reflects a common debate between administrative role-mapping and process-driven identification. Comment [1] correctly notes that RACI charts delineate responsibilities but overlooks that ISACA prioritizes process ownership for initial stakeholder discovery. Comments [2] and [3] reinforce the community consensus that option B aligns with official CRISC exam logic and real-world risk governance practices.

Exam Strategy

When tackling CRISC stakeholder identification questions, always trace risks back to the business processes they impact. Prioritize answers that designate process owners as primary stakeholders over generic management consultations or post-identification documentation tools.

Related Analysis

Practice All CRISC Questions

Access 332 questions with complete answers and detailed explanations.

View Full CRISC Practice Test →

← Back to CRISC Study Guide