Which of the following is the MOST important criteria for selecting key risk indicators (KRIs)?
Correct Answer: D
Sensitivity and reliability are the most important criteria for selecting KRIs, as they indicate how well the KRIs reflect the changes in the risk level and how consistent and accurate the KRIs are in measuring the risk.
Sensitivity means that the KRIs should respond quickly and proportionally to the variations in the risk exposure, and provide early warning signals of potential risk events. Reliability means that the KRIs should be based on valid and verifiable data sources, and produce consistent and comparable results over time and across different units or functions. Historical data availability, implementation and reporting effort, and ability to display trends are also useful criteria, but they are not as critical as sensitivity and reliability.
References:
*ISACA, Risk IT Framework, 2nd Edition, 2019, p. 751
*ISACA, Risk and Information Systems Control Review Manual, 7th Edition, 2020, p. 2122