Risk Implementation
About 25% of the CIS-RC exam — see all 7 domains.
Risk Management identifies, assesses, monitors, and responds to risk across the scoped enterprise.
Risk framework. A risk framework groups risk statements into manageable categories/methodologies so large risk libraries stay organized, and it defines the scoring methodology (qualitative vs quantitative, scales, calculation). You associate risk statements to a framework.
Risk statement. A reusable definition of a potential risk ("the thing that could happen"), independent of where it applies. Risk statements are scoped to profiles/entities, which generates risks (instances) in the risk register.
Risk (register). A risk is the scoped instance of a risk statement tied to a profile/entity, tracked in the risk register with owner, scores, treatment, and lifecycle state.
Risk assessment / scoring. Risk is evaluated typically on inherent vs residual dimensions using likelihood × impact (significance) to produce a risk score. Methodologies can be qualitative (scales like Low/Med/High) or quantitative (numeric/monetary). Risk appetite and tolerance thresholds determine whether a risk is acceptable.
Risk assessment methodologies. Assessments can be driven by assessment questionnaires/surveys sent to risk owners/stakeholders, by calculated scores from indicators, or by manual scoring. Reassessment can be scheduled.
Indicators and KRIs.
- Indicators are automated or manual tests/measurements attached to controls or risks; they pull data from the platform (or external sources) to evaluate effectiveness or exposure on a schedule.
- Control indicators evaluate control effectiveness; risk indicators measure risk exposure.
- Key Risk Indicators (KRIs) are higher-level metrics that signal changing risk levels against thresholds; breaches can trigger alerts, tasks, or risk re-scoring. (Note: ServiceNow also uses GRC Metrics in IRM for broader periodic trend tracking, distinct from real-time indicators.)
Risk response / treatment. For each risk: Accept, Avoid, Mitigate (treat), or Transfer. Mitigation links to controls and remediation; issues capture problems needing action.
Advanced Risk and continuous monitoring. GRC: Advanced Risk extends core Risk with enhanced risk assessment, continuous monitoring of risks and controls, and richer frameworks. Continuous monitoring evaluates risks/controls automatically between formal assessments using indicators.
Exam gotchas:
- Risk statement = definition; Risk = scoped instance in the register (parallels objective→control).
- Inherent (before controls) vs residual (after controls) risk.
- KRI = threshold-based signal; indicator = the underlying automated/manual measurement.
Sample questions from this domain
Three of the 75 in this domain, with the reasoning. The full set is in the question bank.
In Risk Management, what is the risk register?
- A. A list of authority documents
- B. A profile type
- C. The central repository of identified risks tracked by the organization ✓
- D. A schedule of attestations
Why: The risk register is the central repository of identified risks. It is not a list of authority documents, a profile type, or an attestation schedule.
What is a risk statement in Risk Management?
- A. A remediation task
- B. A control test result
- C. A reusable definition of a risk that can be applied to profiles to create specific risk records ✓
- D. An authority document citation
Why: A risk statement is a reusable definition applied to profiles to create specific risk records. It is not a control test result, a citation, or a remediation task.
How is inherent risk generally distinguished from residual risk?
- A. Inherent risk applies only to audits
- B. Inherent risk is the risk before controls/mitigation; residual risk is the risk remaining after controls are applied ✓
- C. Inherent risk is after controls and residual risk is before controls
- D. They are the same value
Why: Inherent risk is measured before controls; residual risk is what remains after controls/mitigation. The reverse definition is wrong, they are not equal, and inherent risk is not audit-only.