The primary purpose of providing timely and accurate risk information to stakeholders is to facilitate risk-based decision making. Stakeholders need this information to understand the risks associated with different options and make informed decisions that align with the organization's risk appetite and objectives.
While risk information can inform risk appetite (A), that's not the primary purpose of providing the information. Developing KRIs (C) is part of risk monitoring, not communication.
[Reference: ISACA materials on risk communication and reporting, often within the Risk IT Framework and related publications, emphasize the role of risk information in enabling informed decision making. Stakeholders need accurate and timely information to make effective choices., ]
Submit