CRISC
What should you ask in a CRISC interview, and how should candidates answer?
A CRISC says someone can identify, assess and treat IT risk in business terms. These questions test the four exam domains in practice, with what a strong answer covers. Candidates get the questions to prepare for and three to ask back.
What should an employer ask a CRISC candidate?
Each question maps to an exam domain, so you test what the role needs. Score each answer 1 to 4 on the free scorecard below.
How would you set risk appetite and tolerance for IT risk?
Listen for: Appetite set by the board, tolerances that can be measured, and a clear link to enterprise risk management.
Domain 1: Governance
Explain how the three lines of defense work here.
Listen for: The business owns risk, risk and compliance oversee it, internal audit gives independent assurance.
Domain 1: Governance
Build me a risk scenario for a cloud outage.
Listen for: Threat, asset, event and consequence, then likelihood and impact, and a named owner.
Domain 2: Risk Assessment
What goes into a good risk register entry?
Listen for: A clear description, an owner, inherent and residual ratings, the controls, actions and dates.
Domain 2: Risk Assessment
How do you choose a risk response?
Listen for: Accept, mitigate, transfer or avoid, weighed on cost against benefit, signed off by the owner within appetite.
Domain 3: Risk Response and Reporting
How do you know a control is effective?
Listen for: Design and operating effectiveness, a testing method, and evidence, not assurance by assertion.
Domain 3: Risk Response and Reporting
Which key risk indicators would you report to the board?
Listen for: A few leading indicators with thresholds tied to appetite, shown as trends.
Domain 3: Risk Response and Reporting
How do new technologies such as AI enter your risk process?
Listen for: Assess before adoption, watch the data lifecycle, apply security principles, and track emerging risk.
Domain 4: Technology and Security
CRISC interview scorecard
CRISC interview scorecard
Candidate: ______ Interviewer: ______ Date: ______
| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How would you set risk appetite and tolerance for IT risk? | Appetite set by the board, tolerances that can be measured, and a clear link to enterprise risk management. | |
| 2 | Explain how the three lines of defense work here. | The business owns risk, risk and compliance oversee it, internal audit gives independent assurance. | |
| 3 | Build me a risk scenario for a cloud outage. | Threat, asset, event and consequence, then likelihood and impact, and a named owner. | |
| 4 | What goes into a good risk register entry? | A clear description, an owner, inherent and residual ratings, the controls, actions and dates. | |
| 5 | How do you choose a risk response? | Accept, mitigate, transfer or avoid, weighed on cost against benefit, signed off by the owner within appetite. | |
| 6 | How do you know a control is effective? | Design and operating effectiveness, a testing method, and evidence, not assurance by assertion. | |
| 7 | Which key risk indicators would you report to the board? | A few leading indicators with thresholds tied to appetite, shown as trends. | |
| 8 | How do new technologies such as AI enter your risk process? | Assess before adoption, watch the data lifecycle, apply security principles, and track emerging risk. |
Source: https://credentialpress.com/guides/crisc-interview-questions
Which questions should a CRISC candidate prepare for?
Why CRISC?
How to answer: It shows you can run IT risk the way the business sees it. Say where you have done that.
Tell me about a risk you escalated.
How to answer: Why it exceeded appetite, who decided, and what happened next.
How do you work with internal audit?
How to answer: Shared view of risk, no duplicated testing, and findings tracked to closure.
How do you get business owners to own their risks?
How to answer: Plain language, their objectives first, and decisions recorded in their name.
What should a candidate ask the employer?
- Is there a board-approved risk appetite statement?
- Who owns the risk register, and how often is it reviewed?
- Which risks keep the board up at night?
Where next?
Also free: the CRISC mind map, plus every other credential on our study tools page. For the full syllabus, the CRISC Exam Guide and the CRISC Practice Questions go domain by domain.
Frequently asked questions
What should an employer ask a CRISC candidate?
Questions that test each exam domain in practice, for example: How would you set risk appetite and tolerance for IT risk? Explain how the three lines of defense work here. Build me a risk scenario for a cloud outage.
What should a CRISC candidate ask the employer?
Is there a board-approved risk appetite statement? Who owns the risk register, and how often is it reviewed? Which risks keep the board up at night?
How should a candidate prepare for a CRISC interview?
It shows you can run IT risk the way the business sees it. Say where you have done that.
Which books go deeper on CRISC?

Certified in Risk and Information Systems Control. 14 chapters, 420 pages.

Practice questions with full rationales, sized to the published domain weights. 220 pages.
Sources
Credential Press is independent of ISACA.