# CRISC interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How would you set risk appetite and tolerance for IT risk? | Appetite set by the board, tolerances that can be measured, and a clear link to enterprise risk management. | |
| 2 | Explain how the three lines of defense work here. | The business owns risk, risk and compliance oversee it, internal audit gives independent assurance. | |
| 3 | Build me a risk scenario for a cloud outage. | Threat, asset, event and consequence, then likelihood and impact, and a named owner. | |
| 4 | What goes into a good risk register entry? | A clear description, an owner, inherent and residual ratings, the controls, actions and dates. | |
| 5 | How do you choose a risk response? | Accept, mitigate, transfer or avoid, weighed on cost against benefit, signed off by the owner within appetite. | |
| 6 | How do you know a control is effective? | Design and operating effectiveness, a testing method, and evidence, not assurance by assertion. | |
| 7 | Which key risk indicators would you report to the board? | A few leading indicators with thresholds tied to appetite, shown as trends. | |
| 8 | How do new technologies such as AI enter your risk process? | Assess before adoption, watch the data lifecycle, apply security principles, and track emerging risk. | |

Source: https://credentialpress.com/guides/crisc-interview-questions
