A risk manager persona needs to assess and treat risks without redesigning entity types. How should roles be separated?
Select an answer to reveal the explanation.
Short Explanation
Risk managers play the game; GRC admins paint the field lines. Assessing and treating risks should not require redesigning entity types every sprint. Split those personas so day-to-day risk work stays safe from accidental model changes.
Full Explanation
Persona boundaries in IRM separate operational risk management (assess, respond, monitor) from administrative configuration of the entity framework. Risk managers should not need GRC admin rights to redesign entity types as part of normal assessment. Clear role separation protects the data model while enabling risk lifecycle work.