How to Identify Business Stakeholders for IT Risk Scenarios?
Which of the following is MOST helpful in identifying appropriate business stakeholders to construct and assess IT risk scenarios?
Community Votes
67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests your understanding of linking IT risks to business process owners, while the common trap involves choosing administrative tools like RACI charts that assume stakeholders are already defined.
This CRISC practice question examines the most effective approach for identifying business stakeholders during IT risk scenario development, with strong community consensus supporting process-based mapping.
Option A (Reviewing RACI charts) is the most frequent distractor; while RACI matrices clarify responsibilities, they are typically utilized after stakeholders have been identified through process mapping, making them less effective for initial discovery.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Mapping risk events to related business processes directly reveals the individuals responsible for those operations. In CRISC methodology, business process owners are the primary stakeholders who must participate in constructing and assessing IT risk scenarios. This approach ensures comprehensive coverage of organizational functions and establishes clear accountability before quantitative analysis begins.Why the Other Options Are Wrong
Reviewing RACI charts (Option A) defines roles and responsibilities but assumes stakeholders and processes are already established, making it a secondary step rather than an identification tool. Consulting senior management (Option C) lacks systematic rigor and often overlooks mid-level process owners who possess granular risk knowledge. Conducting risk and business impact analyses (Option D) focuses on quantifying likelihood and financial impact, not on determining who should be involved in the scenario-building phase.Community Comment Notes
The voting split reflects a common debate between administrative role-mapping and process-driven identification. Comment [1] correctly notes that RACI charts delineate responsibilities but overlooks that ISACA prioritizes process ownership for initial stakeholder discovery. Comments [2] and [3] reinforce the community consensus that option B aligns with official CRISC exam logic and real-world risk governance practices.Exam Strategy
When tackling CRISC stakeholder identification questions, always trace risks back to the business processes they impact. Prioritize answers that designate process owners as primary stakeholders over generic management consultations or post-identification documentation tools.
Related Analysis
Practice All CRISC Questions
Access 332 questions with complete answers and detailed explanations.
View Full CRISC Practice Test →