An organization's board of directors wants to identify and evaluate the most significant risks to its long-term strategy and business model, such as disruptive technologies, major shifts in consumer behavior, and geopolitical events. Which risk assessment approach would be most suitable for this purpose?
- A bottom-up risk assessment focused on process-level controls in the accounting department.
- A compliance audit against current industry regulations.
- A top-down strategic risk assessment involving senior leadership and the board. (correct answer)
- A review of IT help desk tickets to identify recurring system issues.
Explanation: The correct answer is C. A top-down approach begins at the entity level with the organization's objectives and strategies. It is ideal for identifying the high-level, significant risks that could impede the achievement of those long-term goals. This aligns perfectly with the board's focus on strategic threats. A and D are examples of bottom-up approaches that identify more granular, operational risks but would likely miss the major strategic risks. B is too narrow, focusing only on compliance risk.