A - No - "Risk" does not necessarily mean IT systems, the Risk committee addresses all forms of risk. B - Yes - For example, one entity outsourcing the management of some systems that other entities may have strict controls over access (PII for example) C - No - The GC can consolidate individual IT risks from the individual entities with their overall risk and then consolidate the entities for themselves. D - No - Prioritising risks is the job of the sub-committee, but does not require a CISO for this.