CRISC

What should you ask in a CRISC interview, and how should candidates answer?

A CRISC says someone can identify, assess and treat IT risk in business terms. These questions test the four exam domains in practice, with what a strong answer covers. Candidates get the questions to prepare for and three to ask back.

What should an employer ask a CRISC candidate?

Each question maps to an exam domain, so you test what the role needs. Score each answer 1 to 4 on the free scorecard below.

  1. How would you set risk appetite and tolerance for IT risk?

    Listen for: Appetite set by the board, tolerances that can be measured, and a clear link to enterprise risk management.

    Domain 1: Governance

  2. Explain how the three lines of defense work here.

    Listen for: The business owns risk, risk and compliance oversee it, internal audit gives independent assurance.

    Domain 1: Governance

  3. Build me a risk scenario for a cloud outage.

    Listen for: Threat, asset, event and consequence, then likelihood and impact, and a named owner.

    Domain 2: Risk Assessment

  4. What goes into a good risk register entry?

    Listen for: A clear description, an owner, inherent and residual ratings, the controls, actions and dates.

    Domain 2: Risk Assessment

  5. How do you choose a risk response?

    Listen for: Accept, mitigate, transfer or avoid, weighed on cost against benefit, signed off by the owner within appetite.

    Domain 3: Risk Response and Reporting

  6. How do you know a control is effective?

    Listen for: Design and operating effectiveness, a testing method, and evidence, not assurance by assertion.

    Domain 3: Risk Response and Reporting

  7. Which key risk indicators would you report to the board?

    Listen for: A few leading indicators with thresholds tied to appetite, shown as trends.

    Domain 3: Risk Response and Reporting

  8. How do new technologies such as AI enter your risk process?

    Listen for: Assess before adoption, watch the data lifecycle, apply security principles, and track emerging risk.

    Domain 4: Technology and Security

CRISC interview scorecard

CRISC interview scorecard

Candidate: ______ Interviewer: ______ Date: ______

#QuestionListen forScore 1 to 4
1How would you set risk appetite and tolerance for IT risk?Appetite set by the board, tolerances that can be measured, and a clear link to enterprise risk management.
2Explain how the three lines of defense work here.The business owns risk, risk and compliance oversee it, internal audit gives independent assurance.
3Build me a risk scenario for a cloud outage.Threat, asset, event and consequence, then likelihood and impact, and a named owner.
4What goes into a good risk register entry?A clear description, an owner, inherent and residual ratings, the controls, actions and dates.
5How do you choose a risk response?Accept, mitigate, transfer or avoid, weighed on cost against benefit, signed off by the owner within appetite.
6How do you know a control is effective?Design and operating effectiveness, a testing method, and evidence, not assurance by assertion.
7Which key risk indicators would you report to the board?A few leading indicators with thresholds tied to appetite, shown as trends.
8How do new technologies such as AI enter your risk process?Assess before adoption, watch the data lifecycle, apply security principles, and track emerging risk.

Source: https://credentialpress.com/guides/crisc-interview-questions

Which questions should a CRISC candidate prepare for?

  1. Why CRISC?

    How to answer: It shows you can run IT risk the way the business sees it. Say where you have done that.

  2. Tell me about a risk you escalated.

    How to answer: Why it exceeded appetite, who decided, and what happened next.

  3. How do you work with internal audit?

    How to answer: Shared view of risk, no duplicated testing, and findings tracked to closure.

  4. How do you get business owners to own their risks?

    How to answer: Plain language, their objectives first, and decisions recorded in their name.

What should a candidate ask the employer?

  • Is there a board-approved risk appetite statement?
  • Who owns the risk register, and how often is it reviewed?
  • Which risks keep the board up at night?

Where next?

Also free: the CRISC mind map, plus every other credential on our study tools page. For the full syllabus, the CRISC Exam Guide and the CRISC Practice Questions go domain by domain.

Frequently asked questions

What should an employer ask a CRISC candidate?

Questions that test each exam domain in practice, for example: How would you set risk appetite and tolerance for IT risk? Explain how the three lines of defense work here. Build me a risk scenario for a cloud outage.

What should a CRISC candidate ask the employer?

Is there a board-approved risk appetite statement? Who owns the risk register, and how often is it reviewed? Which risks keep the board up at night?

How should a candidate prepare for a CRISC interview?

It shows you can run IT risk the way the business sees it. Say where you have done that.

Which books go deeper on CRISC?

Cover of CRISC Exam Guide

CRISC Exam Guide

Certified in Risk and Information Systems Control. 14 chapters, 420 pages.

Cover of CRISC Practice Questions

CRISC Practice Questions

Practice questions with full rationales, sized to the published domain weights. 220 pages.