CISA Exam · 14 min read 2026 Blueprint Verified

CISA Governance & Management of IT: Risk Identification — Complete Study Guide

Rob Pfleghardt

10-year Price Waterhouse alumnus · Founder of VoraPrep · Former CPA (1987–2024) · with the VoraPrep Editorial Team

CISA Governance & Management of IT: Risk Identification — Complete Study Guide

Key Takeaways

  • Exam Domain: Domain 2: Governance and Management of IT
  • Prioritize threats by business impact; a technical finding is irrelevant without a clear connection to potential business loss.
  • Risk Identification is the formal process of finding, recognizing, and documenting the risks that could prevent an organization from achieving its objectives.
  • The exam assumes you know how an auditor finds risks in the first place.
  • To score well, you need to apply a few core concepts like a practicing auditor.

The CISA exam tests your ability to identify the most significant risk, not just list every possible risk. Candidates fail this section when they spot a technically correct flaw but miss the larger business process failure that the flaw enables.

Quick answer

Risk Identification on the CISA exam is the process of finding and describing risks that could impact business objectives. Questions in Domain 2 test your judgment in prioritizing these risks based on their potential business impact, where a fundamental control failure like poor Segregation of Duties (SoD) outweighs a simple compliance deviation.

CISA Risk Identification at a Glance

  • Exam Domain: Domain 2: Governance and Management of IT
  • Domain Weighting: 20% of the CISA exam (per the 2024 outline)
  • Official Body: ISACA (Information Systems Audit and Control Association)
  • Passing Score: 450 on a scaled score range of 200-800
  • Recommended Study Time: At least 200 hours total for the exam
  • Key Frameworks: COBIT 2019, NIST Special Publications (e.g., SP 800-37)

ISACA's CISA pass rate consistently hovers between 50-55% (ISACA), and misinterpreting risk priority is a major reason candidates fall short.

Key Insights for Passing

  • Prioritize threats by business impact; a technical finding is irrelevant without a clear connection to potential business loss.
  • A missing Segregation of Duties (SoD) is almost always the most critical risk when it appears as an answer choice.
  • Key Risk Indicators (KRIs) are forward-looking metrics that warn of increasing risk exposure before a loss occurs.
  • The Risk Register is the authoritative source for all identified risks, their characteristics, and their current mitigation status.
  • Examiners create tempting distractors by presenting technically accurate but less significant risks alongside a critical business process failure.
  • Your primary job as an IS auditor is to connect IT findings to tangible business consequences like financial loss or reputational damage.

What is Risk Identification?

Risk Identification is the formal process of finding, recognizing, and documenting the risks that could prevent an organization from achieving its objectives. For the CISA exam, this is about applying an auditor's professional skepticism to a business scenario to find the most probable and impactful points of failure.

This topic is a cornerstone of Domain 2, "Governance and Management of IT," which makes up a full 20% of your exam score. You won't be asked to simply define a risk. Instead, you'll get a paragraph describing a situation and be asked, "Which of the following is the greatest concern for the IS auditor?"

Free 5-Min Diagnostic

Studying for CISA CISA2? Benchmark your score in 5 minutes.

Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.

The most common mistake is focusing on symptoms. A candidate might correctly spot that a server is missing a patch. That's a finding. But if the reason it's unpatched is that the person who applies patches also approves the change requests, the fundamental risk is the lack of Segregation of Duties. The exam will test if you can see that deeper, systemic failure. You can see how these judgment-based scenarios are built by trying some free CISA practice questions from VoraPrep.

The Core Methods of Risk Identification

The exam assumes you know how an auditor finds risks in the first place. It's not magic; it's a structured process using specific techniques.

Information Gathering Techniques

These are methods for collecting raw data about processes, controls, and potential issues.
  • Interviews: Speaking with key personnel (system admins, department heads, operators) to understand processes and perceived weaknesses.
  • Document Review: Analyzing policies, procedures, system configurations, past audit reports, and incident logs.
  • Checklists: Using standardized lists of common risks and controls for a specific technology or process to ensure complete coverage.

Analytical Techniques

These are methods for analyzing the collected data to formally identify and define risks.
  • Root Cause Analysis (RCA): A technique used to trace a symptom back to its origin. The "5 Whys" is a common RCA method.
  • Scenario Analysis: Developing hypothetical "what-if" scenarios (e.g., "What if our primary data center goes offline?") to identify potential impacts and control gaps.
  • Data Analysis: Using tools to analyze large datasets (like system logs or transaction records) to identify anomalies or trends that indicate risk.

Key Concepts You Must Master for the Exam

To score well, you need to apply a few core concepts like a practicing auditor. The exam is designed to find out if you can think, not just if you can remember.

The Risk Register: Your Single Source of Truth

A risk register is the central document for risk management. It's a log of all identified risks, including details like a description, potential impact and likelihood, risk owner, and the status of mitigation efforts. If a scenario mentions that risks are tracked informally in spreadsheets or meeting minutes, that is a significant finding indicating a weak risk management process.

Differentiating Risk Types

The exam expects you to classify risks correctly. While many risks overlap, understanding the primary category is key.
  • Strategic Risk: Risk of failing to achieve business objectives (e.g., a new competitor enters the market).
  • Operational Risk: Risk of loss from failed internal processes, people, or systems (e.g., a developer pushes untested code to production). This is the most common category on the exam.
  • Financial Risk: Risk of financial loss (e.g., credit risk, market risk, liquidity risk).
  • Compliance Risk: Risk of legal or regulatory penalties (e.g., failing a GDPR or PCI DSS audit).

KRI vs. KPI: The Predictive vs. Reactive Test

This is a classic CISA exam topic. Key Risk Indicators (KRIs) are predictive, while Key Performance Indicators (KPIs) are reactive. You must know the difference.
FeatureKey Risk Indicator (KRI)Key Performance Indicator (KPI)
PurposeEarly warning signal of rising risk.Measures performance against a goal.
TimingLeading (predictive)Lagging (historical)
Example% increase in failed login attempts.Average time to resolve incidents.
Question it Answers"How likely is a future loss event?""How well did we do last quarter?"

An effective KRI has defined thresholds. For example, if "normal" is 50 failed logins per hour, a KRI threshold might be set at 200, which automatically triggers an alert.

Segregation of Duties (SoD): The Ultimate Red Flag

Segregation of Duties (SoD) is an internal control that requires more than one person to complete a critical task. Its purpose is to prevent fraud and error. In risk identification, an absence of SoD is one of the most severe risks you can find.

If you see a scenario where one person can initiate, approve, and implement a change, that is a massive control failure. When an SoD conflict is an answer choice, it is very often the correct answer because it represents a complete breakdown of a foundational control.

Worked Example: Thinking Like an ISACA Examiner

Let's walk through a typical CISA-style problem. This shows how the exam forces you to weigh different types of risk against each other.

The Scenario

An IS auditor is reviewing the change management process for "Global Logistics Inc.," a company that relies on a custom-built enterprise resource planning (ERP) system for its core operations. The auditor observes the following:
  1. Developers have direct administrative access to the production ERP environment to deploy code.
  2. Change requests are documented in an internal wiki, but there is no formal approval workflow in the system.
  3. The company recently experienced a 2-hour ERP outage after a faulty code push, resulting in an estimated business loss of $150,000.
  4. User access reviews for the ERP system are scheduled to be performed annually, but the last one was completed 18 months ago.
The Question: Which of the following findings represents the MOST significant risk to Global Logistics Inc.?
A. The last user access review is six months overdue.
B. The financial loss from the recent outage was not formally quantified by the risk team.
C. Change requests are not managed through a formal approval workflow.
D. Developers have administrative access to the production environment.

Step-by-Step Solution

  1. Analyze the Options: Let's break down what each option represents.
  • A (Overdue Access Review): This is a valid compliance finding and a moderate operational risk. It means inappropriate access might exist.
  • B (Loss Not Quantified): This is a weakness in the risk management process after an event. It's a procedural gap but doesn't represent a direct, ongoing threat.
  • C (No Formal Workflow): This is a significant process weakness. It suggests changes can be made without proper oversight, which could lead to unauthorized or faulty changes.
  • D (Developer Production Access): This is a critical failure of Segregation of Duties. The people writing the code can also push it live, bypassing any potential testing and approval.
  1. Identify the Tempting Wrong Answer: Option C is very tempting. The lack of a formal workflow is a serious problem and is a direct cause of the recent outage. Many candidates will stop here. It's a good answer, but it's not the best answer.
  2. Find the Root Cause (The Examiner's Mindset): The real question is why the lack of a formal workflow is so dangerous. It's dangerous because the people who have the ability to make changes (developers) can do so without any check or balance. Option D describes the condition that makes this possible: developers have the keys to the kingdom.

This is a classic SoD violation. The developer's role (to create/modify) is not segregated from the operations role (to deploy/run). This single failure enables unauthorized changes, fraud, and catastrophic errors. While the missing workflow (C) is a problem, the direct administrative access (D) is the fundamental control breakdown that enables the risk. It is the root cause of the root cause.

  1. The Final Verdict: The correct answer is D. It represents a complete failure of a foundational control (SoD), which directly leads to the type of incident the company has already experienced. The overdue access review is a lesser risk, and the unquantified loss is a reactive issue, not a preventative control failure.

This example highlights the core challenge: you must trace the problem to the most fundamental control that has failed. For more practice on these nuanced questions, you can review the full CISA exam details and format breakdown.

Test Your Judgment: CISA Practice Questions

Theory is one thing, but applying it under pressure is another. Here are a few sample questions modeled after the real CISA exam.

---

✨ Free Domain Calculator

Calculate Your CISA Study Hours by Domain

See the exact domain-by-domain study breakdown reflecting the 2024 ISACA Job Practice weighting shifts.

Calculate CISA Study Plan →
Question 1 During an audit of a financial services firm's application development process, an IS auditor discovers that a senior developer is responsible for writing code, performing quality assurance (QA) testing on their own code, and deploying the approved code into the production environment. Which of the following is the auditor's GREATEST concern?
A. The developer may not have adequate training in QA testing methodologies.
B. Application performance may be negatively impacted by inefficient code.
C. The firm may not be in compliance with its documented change management policy.
D. A lack of segregation of duties could allow unauthorized changes to be implemented.
Answer: D. A lack of segregation of duties could allow unauthorized changes to be implemented.
  • Explanation: This is a clear Segregation of Duties (SoD) violation. A single individual controls the entire development-to-deployment pipeline, creating a significant risk of fraud or major error. Option A is a concern but secondary to the control failure. Option B is an operational issue, but the SoD failure is a more fundamental risk. Option C is likely true, but D explains why this non-compliance is so dangerous.

---

Question 2 An IS auditor is reviewing a new cybersecurity monitoring program for an online retailer. The auditor should expect that Key Risk Indicators (KRIs) have been developed to:
A. provide an early warning of potential security breaches.
B. measure the financial impact of past security incidents.
C. document the number of security policies approved by management.
D. track the completion rate of security awareness training for employees.
Answer: A. provide an early warning of potential security breaches.
  • Explanation: The primary purpose of a KRI is to be a leading indicator. It's designed to signal a rising risk before it becomes a loss event. Options B, C, and D are all lagging indicators or process metrics; they measure things that have already happened or the status of compliance activities, not emerging threats.

---

Question 3 During an audit of a manufacturing firm's operational technology (OT) environment, an IS auditor identifies that the SCADA system, which controls a critical production line, has not been patched in over three years. The plant manager explains that they follow the vendor's guidance, which is "if it isn't broken, don't fix it," to ensure system stability. The MOST important action for the IS auditor is to:
A. recommend immediate patching of the system to the latest version.
B. document the finding and note management's acceptance of the risk.
C. identify and document the potential business impact of a system compromise.
D. verify if the vendor's guidance is documented in the service level agreement (SLA).
Answer: C. identify and document the potential business impact of a system compromise.
  • Explanation: The auditor's primary role is to connect technical findings to business risk. The first and most critical step is to articulate the risk in business terms. What would happen if this unpatched system were compromised? Quantifying this impact (e.g., "A shutdown of this line would cost $500,000 per day in lost revenue") is essential for management to make an informed decision. Recommending an operational action like immediate patching (A) is premature without this risk context. Documenting risk acceptance (B) can only happen after the risk is fully understood by management.

--- Want to drill down on this topic? You can practice hundreds of Risk Identification questions in VoraPrep's adaptive quiz engine.

A Practical Study Plan for Risk Identification

Your study plan should focus on application, not memorization. It’s not about knowing 100 types of risk; it’s about correctly identifying the most critical one in a given scenario. The Myth vs. Reality Drill:
  • The Myth: "I need to memorize all the risks listed in the COBIT framework."
  • The Reality: "I need to read a business scenario and pinpoint the weakness that has the greatest potential impact on the organization's objectives."
Your Weekly Drill: For every practice question you get wrong on this topic, don't just read the explanation. Write one single sentence that starts with: "The business impact of the correct answer is greater because..." This forces you to think in terms of consequences, which is exactly what the exam requires. This topic connects heavily to other areas, especially the CISA Governance & Management of IT: Risk Assessment Methodologies — Complete Study Guide, as identification is the first step before assessment.

Frequently asked questions

How many questions on Risk Identification appear on the CISA exam? Risk Identification is a key task within Domain 2, which constitutes 20% of the exam. While ISACA does not provide an exact number per task, you can expect a significant portion of the Domain 2 questions, likely 10-15 questions, to directly test your ability to identify and prioritize risks. What's the best way to study Risk Identification? The most effective method is working through high-quality, scenario-based practice questions. Focus on understanding the reasoning behind the correct answer. For each question, ask yourself, "Why is this risk more significant than the others?" This active learning is far more effective than passively reading a textbook. Is Risk Identification tested in simulations or only MCQ? The CISA exam consists entirely of multiple-choice questions (MCQs). There are no simulation-based questions. However, the MCQs are written as "mini case studies" that require you to apply knowledge to a realistic scenario, effectively testing the same skills a simulation would. How long should I spend studying Risk Identification? As part of your overall study plan for Domain 2, you should allocate approximately 15-20 hours specifically to Risk Identification and its related concepts. This includes reading source material and, most importantly, completing and reviewing hundreds of practice questions.
⚡ Instant Knowledge Check · 1-Click Test Drive
CISA Domain 5: Protection of Information Assets

When conducting an IS audit of an enterprise cloud infrastructure environment, which of the following identity and access management (IAM) findings represents the GREATEST information security risk?

Official resources and references

--- Ready to Pass Your CISA Exam?

The difference between passing and failing is learning to think like the examiner. VoraPrep's adaptive learning platform and 2,300+ practice questions are designed to do exactly that. With detailed explanations for every answer and our 24/7 AI tutor, Vory, we target your weak spots until they become strengths.

Visit voraprep.com to get started.

Start Your Free 14-Day Trial at voraprep.com →
RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding a CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →
Free Diagnostic Assessment

Find your exact CISA weak spots in 10 minutes.

Most candidates fail because they study blindly. Take our free 10-question diagnostic to identify your weakest blueprint topics and receive a custom 12-week study plan PDF generated instantly.

Keep reading

Free 5-min CISA diagnostic + 12-week plan PDF

Start →
CISA 1:1 Prometric Simulator

2,300+ practice questions with instant Socratic feedback