正解:B
Inherent risk reflects exposure before controls. When regulatory requirements change, they can alter compliance obligations, legal exposure, and the baseline inherent risk of processes.
ISACA's CRISC framework specifies:
"Significant changes to regulatory or legal environments are triggers for reassessing inherent and residual risk."
* A (risk tolerance) affects acceptance, not inherent risk itself.
* C (KRIs) and D (benchmarks) measure and compare risk but do not trigger reassessment directly.
Hence, B is correct.
CRISC Reference: Domain 2 - IT Risk Assessment, Topic: Risk Triggers and Environmental Changes.