Why pre-screen IT risk managers before the CISO and audit committee panel
Pre-screening IT risk managers protects the time of your CISO, internal audit lead and audit committee members, who are the hardest calendars to book. Applicants arrive from Big Four advisory, second line risk teams, infrastructure engineering and compliance, and every resume lists NIST CSF, ISO 27001, CRISC and "risk register ownership". A ten minute screen shows whether they can put a number on a risk, name a control they tested themselves, and describe what happened when a risk owner refused to fund remediation.
What actually matters when screening IT Risk Manager candidates
- 01
Technical depth
Probe how they quantify technology risk and whether they understand the systems behind the register entries.
- 02
Real incidents and findings
Look for risks they actually retired, and any that materialised on their watch.
- 03
Risk judgement
Test how they judge an accepted risk that the business has been carrying comfortably for three years.
- 04
Getting things fixed
Assess how they get risk owners to act when nothing has gone wrong yet and budgets are committed elsewhere.
Pre-screening questions to ask IT Risk Manager candidates
11 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.
Technical depth
4 questions01How do you incorporate quantitative risk analysis into a risk assessment? Walk me through one risk you put a number on.
Listen forA named risk with an annualised loss estimate or Monte Carlo range, the data inputs used (incident history, records at stake, downtime cost), and stated assumptions.
They describe only heat maps, five by five matrices or colour ratings with no loss figures or data inputs behind them.
02Which risk assessment methodology do you actually use, and how do you set inherent versus residual ratings?
Listen forA specific framework in practice (NIST 800-30, ISO 27005, FAIR, COSO) with a concrete example of how a control test moved a residual rating.
They recite framework names without explaining how control effectiveness changes a rating on any real entry.
03Describe your hands-on experience with cyber security and data protection controls: which ones have you tested yourself?
Listen forNamed controls they have examined, such as privileged access reviews, encryption at rest, MFA coverage, backup restore tests or DLP rules, with what they found.
They can only talk about controls at policy level and cannot explain how any of them work technically.
04How familiar are you with the regulations that drive your risk register, such as GDPR, CCPA, DORA or SOX?
Listen forSpecific obligations tied to controls: 72 hour breach notification, records of processing, data subject requests, or SOX ITGC scoping for financial systems.
They list regulation acronyms but cannot connect any single article or requirement to a control or register entry.
Real incidents and findings
2 questions05Tell me about a risk you identified and actually retired. What was the residual rating before and after?
Listen forA named system, the exposure, the remediation funded, the owner who signed off, timeline to closure, and the measurable drop in residual risk.
The example ends at "I escalated it" with no evidence the risk was ever closed or reduced.
06Have you developed disaster recovery plans, and when did you last see one tested against a real RTO?
Listen forConcrete RTO and RPO targets, a tabletop or failover exercise they ran, and the gaps the test exposed (stale runbooks, untested restores, missing dependencies).
They wrote DR documentation that was never exercised, or cannot state any RTO or RPO they worked to.
Reporting and influence
2 questions07Take 60 seconds: present a high severity risk finding to a non-technical executive audience as if the board is listening.
Listen forPlain language, business impact framed in money, downtime or regulatory exposure, a clear decision request, and no unexplained jargon or acronyms.
They narrate technical detail, CVSS scores or tool output without ever naming the business consequence or the decision needed.
08How have you communicated IT risk to senior leadership when they did not want to hear it?
Listen forA specific forum (risk committee, exec steering group), the resistance they met, and how they used data, peer incidents or regulatory exposure to shift the decision.
They only escalate by email or report upward, and have never had a documented disagreement with a risk owner.
Credentials and logistics
3 questions09Have you led a team or a second line function managing IT risk? Describe the reporting line.
Listen forClear scope: direct reports or matrixed assessors, who they reported to (CISO, CRO, audit committee), and what they were accountable for delivering.
They claim leadership but describe only contributing assessments inside someone else's programme.
10Which enterprise risk or GRC platforms have you worked in, and what did you configure yourself?
Listen forNamed tools (Archer, ServiceNow IRM, LogicGate, OneTrust, MetricStream) with specifics on register structure, workflows, control libraries or reporting they built.
Tool exposure limited to reading dashboards someone else built, with spreadsheets as the real system of record.
11Which IT risk certifications do you hold (CRISC, CISM, CISA, ISO 27001 Lead Auditor), and when did you earn them?
Listen forCertifications named with dates and current standing, plus honesty about which are in progress and any audit or assessment experience behind them.
Vague or expired claims, or listing credentials they are only planning to attempt.
How to score responses
Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.
Technical depth
35%5Understands the systems behind each risk and can quantify exposure rather than colouring a heat map.
Real incidents and findings
30%5Names risks they got closed, and is candid about one that materialised and what the register missed.
Risk judgement
20%5Re-tests stale accepted risks against current exposure rather than rolling them forward unchallenged.
Getting things fixed
15%5Moves risk owners to act pre-incident by framing exposure in business terms, with treatments actually delivered.
Risk managers live or die on how they sound in front of an audit committee. Async video lets you hear whether they can explain a technical exposure to non-technical executives without jargon or hedging, before you book the panel.
Try it on HirevireScreening FAQ
Process basics
What should an IT risk manager screening cover before the panel stage?
Cover four areas: how they size a risk in loss terms, one incident or audit finding they personally worked, how they challenge a risk the business accepted years ago, and how they move remediation forward without an outage to point at. Certifications and GRC tooling can be captured as short text answers rather than spending live interview minutes on them.
Do CRISC or CISM certifications matter when screening IT risk managers?
They matter as a filter, not as evidence. CRISC, CISM and CISA confirm exposure to control language and assessment methodology, which helps in regulated environments where auditors expect it. Ask which one they hold, when they earned it, and then test whether they can quantify a single risk from their current register in their own words.
Evaluating answers
How do you tell a real risk practitioner from someone who maintains a register?
Listen for specifics that only an owner would know: the system name, the control that failed, the residual rating before and after, the risk owner's title, and the date the risk closed. Register maintainers describe process ("quarterly refresh cycles", "heat maps") without naming a single risk they retired or the money it saved.
What are the biggest red flags in IT risk manager screening answers?
The biggest red flags are risk ratings with no basis ("we scored it high"), no example of a risk that materialised, and blaming the business for every unfunded remediation. Also watch for candidates who cannot explain the technology behind an entry, such as what unsupported TLS versions or missing privileged access controls actually expose.
























