New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-31000-Lead-Risk-Manager Exam - Topic 5 Question 2 Discussion

Actual exam question for PECB's ISO-31000-Lead-Risk-Manager exam
Question #: 2
Topic #: 5
[All ISO-31000-Lead-Risk-Manager Questions]

Scenario 6:

Trunroll is a fast-food chain headquartered in Chicago, Illinois, specializing in wraps, burritos, and quick-serve snacks through both company-owned and franchised outlets across several states. Recently, the company identified two major risks: increased dependence on third-party delivery platforms that could disrupt customer service if contracts were to fail or fees rose sharply, and stricter health and safety inspections that might expose vulnerabilities in hygiene practices across certain franchise locations. Therefore, the top management of Trunroll adopted a structured risk management process based on ISO 31000 guidelines to systematically identify, assess, and mitigate risks, embedding risk awareness into daily operations and strengthening resilience against future disruptions.

To address these risks, Trunroll outlined and documented clear actions with defined responsibilities and timelines. Regarding the dependence on third-party delivery platforms, the company decided not to move forward with planned partnerships with third-party delivery apps, as the risk of losing control over the customer experience and rising costs outweighed the potential benefits.

To address stricter health inspections across franchises, Trunroll invested in stronger hygiene protocols, mandatory staff training, and upgraded monitoring systems to reduce the likelihood of violations. Yet, management understood that some exposure would remain even after these measures. To address this risk, they decided to use one of the insurance methods, reserving internal financial resources to cover unexpected losses or penalties, ensuring the remaining risk was managed within acceptable boundaries.

Additionally, Trunroll set up a cloud-based platform to document and maintain risk records. This allowed managers to log supplier inspection results, training outcomes, and incident reports into one secure system, while also providing flexibility to update and scale applications as needed without managing the underlying infrastructure. In doing so, Trunroll ensured that all risk-related information is documented in progress reports and incorporated into mid-term and final evaluations, with risk management being updated regularly to monitor changes and treatments.

Based on the scenario above, answer the following question:

Trunroll documented all risk-related information in progress reports and incorporated it into mid-term and final evaluations. Which organizational level for risk reporting did they consider in this case?

Show Suggested Answer Hide Answer
Suggested Answer: A

The correct answer is A. Corporate level. ISO 31000 emphasizes that risk reporting should support governance, oversight, and strategic decision-making at appropriate organizational levels. Corporate-level risk reporting consolidates risk information across the organization and feeds into mid-term and final evaluations, enabling top management and oversight bodies to monitor performance and risk exposure.

In Scenario 6, Trunroll ensured that risk-related information was incorporated into progress reports and mid-term and final evaluations, and that risk management was updated regularly. These activities are characteristic of corporate-level reporting, which focuses on organization-wide risks, strategic objectives, and resilience.

Program or unit-level reporting would focus on specific departments or functions, while project-level reporting is limited to defined projects with finite timelines. The scenario clearly indicates organization-wide reporting to support top management oversight.

From a PECB ISO 31000 Lead Risk Manager perspective, corporate-level risk reporting ensures alignment with strategy, accountability, and continuous improvement. Therefore, the correct answer is corporate level.


Contribute your Thoughts:

0/2000 characters
Trinidad
5 days ago
I'm not entirely sure, but it seems like they could also be looking at the corporate level since they are documenting everything for mid-term and final evaluations.
upvoted 0 times
...
Rosina
10 days ago
I think they might be focusing on the program/unit level since they are addressing risks across multiple franchises.
upvoted 0 times
...
Muriel
15 days ago
Based on the details provided, I believe the answer is A) Corporate level. Trunroll seems to have implemented a structured risk management process across the entire organization, not just for individual projects or units, which aligns with risk reporting at the corporate level.
upvoted 0 times
...
Reynalda
20 days ago
The scenario mentions that Trunroll set up a cloud-based platform to document and maintain all their risk records, which makes me think they were taking a more holistic, organization-wide approach to risk management. I'm leaning towards the corporate level for this one.
upvoted 0 times
...
Erasmo
26 days ago
Okay, I think I've got it. Trunroll was documenting risk-related information in progress reports and incorporating it into mid-term and final evaluations, which suggests they were considering risk reporting at the corporate level, not just the individual project or unit level.
upvoted 0 times
...
Margret
1 month ago
Hmm, I'm a bit confused about the different organizational levels for risk reporting. I'll need to re-read the scenario carefully to try to figure out which one they focused on.
upvoted 0 times
...
Sherron
1 month ago
This seems like a pretty straightforward risk management case study. I think the key is to identify the different levels of risk reporting that Trunroll considered based on the information provided.
upvoted 0 times
...

Save Cancel