Isaca CRISC Question Answer
Which of the following MUST be captured in a risk treatment plan?
Risk owner
Senior management
Risk register details
Risk financial impact
Each risk in a treatment plan must have a designated risk owner accountable for implementing the mitigation or response.
CRISC states:
“The risk treatment plan must specify the risk owner responsible for implementing chosen treatments for risks exceeding tolerance.”
While financial details and register links are supportive, ownership is mandatory for accountability.
Hence, A. Risk owner is correct.
CRISC Reference: Domain 3 – Risk Response and Mitigation, Topic: Developing and Managing Risk Treatment Plans.
TESTED 19 Jan 2026
Copyright © 2014-2026 ACE4Sure. All Rights Reserved