CRISC Certified in Risk and Information Systems Control – Question276

You and your project team have identified a few risk events in the project and recorded the events in the risk register. Part of the recording of the events includes the identification of a risk owner. Who is a risk owner?

A.
A risk owner is the party that will monitor the risk events.
B. A risk owner is the party that will pay for the cost of the risk event if it becomes an issue.
C. A risk owner is the party that has caused the risk event.
D. A risk owner is the party authorized to respond to the risk event.

Correct Answer: D

Explanation:

Explanation:
Risk owner for each risk should be the person who has the most influence over its outcome. Selecting the risk owner thus usually involves considering the source of risk and identifying the person who is best placed to understand and implement what needs to be done. They are also responsible for responding to the event and reporting on the risk status.
Incorrect Answers:
A: A risk owner will monitor the identified risks for status changes, but all project stakeholders should be iteratively looking to identify the risks.
B: Risk owners do not pay for the cost of the risk event.
C: Risk owners are not the people who cause the risk event.