PE PowerExams Prepare. Practice. Pass.
CIS-RC · Domain 5 of 7

Risk Implementation

About 25% of the CIS-RC exam — see all 7 domains.

25%
of the exam
75
practice questions
7
domains total

Risk Management identifies, assesses, monitors, and responds to risk across the scoped enterprise.

Risk framework. A risk framework groups risk statements into manageable categories/methodologies so large risk libraries stay organized, and it defines the scoring methodology (qualitative vs quantitative, scales, calculation). You associate risk statements to a framework.

Risk statement. A reusable definition of a potential risk ("the thing that could happen"), independent of where it applies. Risk statements are scoped to profiles/entities, which generates risks (instances) in the risk register.

Risk (register). A risk is the scoped instance of a risk statement tied to a profile/entity, tracked in the risk register with owner, scores, treatment, and lifecycle state.

Risk assessment / scoring. Risk is evaluated typically on inherent vs residual dimensions using likelihood × impact (significance) to produce a risk score. Methodologies can be qualitative (scales like Low/Med/High) or quantitative (numeric/monetary). Risk appetite and tolerance thresholds determine whether a risk is acceptable.

Risk assessment methodologies. Assessments can be driven by assessment questionnaires/surveys sent to risk owners/stakeholders, by calculated scores from indicators, or by manual scoring. Reassessment can be scheduled.

Indicators and KRIs.

  • Indicators are automated or manual tests/measurements attached to controls or risks; they pull data from the platform (or external sources) to evaluate effectiveness or exposure on a schedule.
  • Control indicators evaluate control effectiveness; risk indicators measure risk exposure.
  • Key Risk Indicators (KRIs) are higher-level metrics that signal changing risk levels against thresholds; breaches can trigger alerts, tasks, or risk re-scoring. (Note: ServiceNow also uses GRC Metrics in IRM for broader periodic trend tracking, distinct from real-time indicators.)

Risk response / treatment. For each risk: Accept, Avoid, Mitigate (treat), or Transfer. Mitigation links to controls and remediation; issues capture problems needing action.

Advanced Risk and continuous monitoring. GRC: Advanced Risk extends core Risk with enhanced risk assessment, continuous monitoring of risks and controls, and richer frameworks. Continuous monitoring evaluates risks/controls automatically between formal assessments using indicators.

Exam gotchas:

  • Risk statement = definition; Risk = scoped instance in the register (parallels objective→control).
  • Inherent (before controls) vs residual (after controls) risk.
  • KRI = threshold-based signal; indicator = the underlying automated/manual measurement.

Sample questions from this domain

Three of the 75 in this domain, with the reasoning. The full set is in the question bank.

Question 1 · easy

In Risk Management, what is the risk register?

  • A. A list of authority documents
  • B. A profile type
  • C. The central repository of identified risks tracked by the organization
  • D. A schedule of attestations

Why: The risk register is the central repository of identified risks. It is not a list of authority documents, a profile type, or an attestation schedule.

Question 2 · easy

What is a risk statement in Risk Management?

  • A. A remediation task
  • B. A control test result
  • C. A reusable definition of a risk that can be applied to profiles to create specific risk records
  • D. An authority document citation

Why: A risk statement is a reusable definition applied to profiles to create specific risk records. It is not a control test result, a citation, or a remediation task.

Question 3 · medium

How is inherent risk generally distinguished from residual risk?

  • A. Inherent risk applies only to audits
  • B. Inherent risk is the risk before controls/mitigation; residual risk is the risk remaining after controls are applied
  • C. Inherent risk is after controls and residual risk is before controls
  • D. They are the same value

Why: Inherent risk is measured before controls; residual risk is what remains after controls/mitigation. The reverse definition is wrong, they are not equal, and inherent risk is not audit-only.