リスク担当者は、リスク所有者が IT 製品のサプライヤーから贈り物を受け取っていたことを知りました。これらの IT 製品の一部は、制御を実施し、リスクを許容レベルまで軽減するために使用されます。リスク担当者が最初に行うべきことは、次のどれですか。
正解:D
Reporting the activity to the supervisor is the first thing that the risk practitioner should do when learning that a risk owner has been accepting gifts from a supplier of IT products. This is because accepting gifts from a supplier of IT products can create a conflict of interest, compromise the integrity and objectivity of the risk owner, and violate the organizational ethics policies. Reporting the activity to the supervisor can help ensure that the issue is escalated to the appropriate authority, investigated, and resolved in a timely and transparent manner. According to the CRISC Review Manual 2022, one of the key risk response techniques is to report the risk to the relevant stakeholders, such as the supervisor1. According to the web search results, reporting the activity to the supervisor is a common and recommended action when encountering a potential ethical violation in the workplace