ITIL 5 Master : Strategic Risk & Resilience (Domain 10)
ITIL 5 – Master : Certified ITIL Master - Domain 10 - Strategic Risk, Resilience, and Portfolio Management
This comprehensive study guide focuses on Domain 10 of the ITIL 5 Master and Strategic Leader syllabi. It explores the critical intersection of strategic direction, risk management, operational resilience, and portfolio-level execution within the context of Digital Product and Service Management (DPSM).
1. Evolution to Digital Product and Service Management (DPSM)
The introduction of ITIL 5 in 2026 marked a fundamental shift from traditional IT management to Digital Product and Service Management (DPSM). This evolution is necessitated by digital transformation, which requires organizations to go beyond modernizing IT infrastructure to fundamentally changing how products and services are designed, delivered, and improved.
Within the ITIL Master framework, strategy is no longer a static document but a unified lifecycle. It serves as one of the four enabling capabilities required for successful operations and transformation, alongside leadership, governance, and management. Strategy is defined as a set of decisions and plans that enable an organization to fulfill its purpose and progress toward its vision. In the ITIL 5 context, strategy determines long-term direction and competitive positioning, guiding resource allocation during “Business as Usual” (BAU) and defining target operating models during periods of disruption.
2. Strategic Direction Setting and Board-Level Governance
The Strategic Leader must align DPSM with enterprise-level governance. This involves several sophisticated frameworks for direction setting:
- Vision, Mission, and Purpose: These form the foundation of the strategy, providing the “why” behind every digital investment.
- Strategy Maps and Wardley Mapping: These tools are used to visualize the value chain and identify which components of a service are commodities versus those that provide a competitive advantage.
- Hoshin Kanri and OKR Cascading: These methodologies ensure that high-level strategic goals are broken down into actionable objectives and key results (OKRs) across the organization.
- The DME Model (Direct, Monitor, Evaluate): This is the core of board-level governance. The board directs by setting strategy and policies, monitors performance against those metrics, and evaluates the results to trigger necessary adjustments.
- Three Lines of Defence: This governance architecture ensures effective risk management:
- First Line: Management and internal controls (operational).
- Second Line: Risk management and compliance functions (oversight).
- Third Line: Internal audit (independent assurance).
3. The Strategic Risk Register and Portfolio Risk Management
A cornerstone of Domain 10 is the Strategic Risk Register. Unlike operational risk registers that focus on technical failures, the strategic version focuses on risks that could prevent the organization from achieving its long-term vision.
Strategic risk management in ITIL 5 involves:
- Identification of Strategic Risks: These include market shifts, digital disruption, regulatory changes (especially regarding AI), and sustainability-related risks.
- Risk-Informed Decision Making: Portfolio managers use the risk register to guide investment prioritization. High-risk, high-reward initiatives are balanced against more stable, foundational services.
- Integration with Portfolio Planning: Risk is not treated as a separate silo; it is embedded in the portfolio management process to ensure that the organizational “bet” on certain digital products is hedged by appropriate controls.
4. Defining Risk Appetite and Tolerance
For an ITIL Master, understanding the distinction between risk appetite and tolerance is critical for strategic alignment:
- Risk Appetite: The broad amount and type of risk that an organization is willing to take in pursuit of its strategic objectives. For example, a firm might have a high appetite for innovation in AI-driven services but a low appetite for risks involving data privacy.
- Risk Tolerance: The specific, measurable deviations from the risk appetite that the organization can withstand. While appetite is a qualitative statement of intent, tolerance provides the quantitative boundaries for operational management.
Setting these levels is a board-level responsibility, ensuring that the Digital and IT strategy does not overextend the organization’s financial or reputational capital.
5. Operational Resilience as a Strategic Differentiator
Operational resilience is the ability of an organization to absorb and adapt in a changing environment to enable it to deliver its objectives. In ITIL 5, resilience is elevated from a technical “backup and recovery” concept to a strategic capability.
Strategic resilience involves:
- Business Continuity and Beyond: Moving from merely “staying online” to ensuring that the core value proposition of digital products remains intact during disruption.
- Adaptive Governance: Creating governance structures that can pivot quickly when internal or external circumstances change.
- Complexity Thinking: Acknowledging that digital ecosystems are complex systems where small changes can have unpredictable effects, requiring a resilient mindset across all four dimensions of service management.
6. Scenario Planning in VUCA Environments
Strategy in ITIL 5 must account for VUCA environments (Volatile, Uncertain, Complex, and Ambiguous). Traditional linear planning is often insufficient in these contexts. Scenario planning allows strategic leaders to:
- Anticipate Multiple Futures: Instead of one forecast, leaders develop multiple plausible scenarios (e.g., “rapid AI adoption” vs. “heavy AI regulation”).
- Test Strategy Robustness: By “wind-tunneling” a strategy against different scenarios, organizations can identify which strategic moves are “no-regrets” and which are highly contingent on specific conditions.
- Identify Early Warning Signals: Scenario planning helps the board identify the metrics that indicate which future is becoming a reality, allowing for faster evaluation and redirection (DME).
7. Portfolio-Level Performance: OKRs and KPIs
Measuring strategic success requires a balanced approach between leading and lagging indicators. ITIL 5 emphasizes the use of Objectives and Key Results (OKRs) alongside Key Performance Indicators (KPIs).
| Metric Type | Focus | Role in Portfolio Management |
|---|---|---|
| OKRs | Aspirational and Outcome-based | Drive transformation and alignment to the digital vision. |
| KPIs | Operational and Output-based | Monitor the health of “Business as Usual” and service performance. |
Strategic leaders use Portfolio level OKRs to ensure that investments are actually delivering the intended value. This includes tracking “Value Stream Metrics” at the portfolio level to ensure end-to-end flow from idea to support is optimized for the organization, not just individual silos.
8. Investment Prioritization and Strategic Sourcing
A key function of the ITIL Strategic Leader is deciding where to allocate capital. This involves the Investment Prioritization process, which is influenced by:
- Business Model Canvas: Understanding how the digital strategy supports the broader business model.
- Target Operating Model (TOM) Design: Deciding what capabilities the organization needs to own versus what it should source.
- Build, Buy, or Partner Decisions: A strategic capability that evaluates whether to develop a product in-house, purchase a solution, or enter a strategic partnership.
- SIAM (Service Integration and Management) at the Strategic Level: Managing a multi-provider ecosystem to ensure that the total portfolio of services remains coherent and value-driven.
9. The ITIL Strategy Management Model
The ITIL Strategy Management Model is structured around two interlinked lifecycles:
- Strategy Development Lifecycle:
- Activities: Plan, Execute, Synthesize, and Reflect.
- Focus: Determining the vision, assessing internal and external environments (using PESTLE: Political, Economic, Social, Technological, Legal, Environmental), and defining strategic objectives.
- Strategy Implementation Lifecycle:
- Focus: Translating strategic objectives into actionable initiatives. This involves selecting execution approaches and balancing transformation initiatives with daily operations.
These cycles work together to ensure that strategy is not just a plan but a living process of continual strategic improvement.
10. AI-Augmented Strategy and Responsible AI Governance
As organizations move into AI-enabled environments, strategic governance must evolve to include Responsible AI. This is a core extension module in ITIL 5 and a key part of strategic leadership.
- AI Strategy Governance: Ensuring that technology investments in AI support business outcomes and do not create unmanaged risks.
- Digital Ethics: Addressing transparency, accountability, and ethical considerations in how data and AI are used.
- Compliance and Regulation: Staying ahead of emerging AI regulations to ensure the organization maintains its “license to operate” in a digital economy.
11. Sustainability and ESG Reporting
Sustainability is no longer an optional “add-on” but a strategic requirement. ITIL 5 integrates sustainability into the core strategy:
- Carbon-Aware Strategy: Considering the environmental impact of digital products and services.
- ESG (Environmental, Social, and Governance) Reporting: Providing the board and stakeholders with measurable data on the organization’s sustainability performance.
- Long-Term Value Creation: Ensuring that the digital strategy contributes to the long-term viability of both the organization and the environment in which it operates.
12. Organizational Change Management (OCM) and Strategic Communication
Strategic success is as much about people as it is about technology. Strategic OCM is required to support the transition to new operating models.
- Strategic Communication: Ensuring that the vision and strategy are communicated effectively to the board and throughout the organization to ensure buy-in.
- Complexity Thinking: Using OCM to manage the cultural shifts required when moving toward product-centric ways of working.
- Leadership and Governance: Developing the strategic capabilities of leaders to act with clarity and confidence in complex environments.
Short-Answer Questions
- What is the primary difference between the Strategy Development Lifecycle and the Strategy Implementation Lifecycle?
- How does the “Three Lines of Defence” model improve strategic governance?
- Define the role of “PESTLE” factors in the Strategy Development Lifecycle.
- Why is “Scenario Planning” particularly valuable in a VUCA environment?
- What is the purpose of “OKR Cascading” in ITIL 5?
- How does “Strategic Risk” differ from “Operational Risk”?
- What are the three components of the “DME” model in board-level governance?
- In the context of investment prioritization, what does “SIAM at the strategic level” refer to?
- What is “Complexity Thinking” and why is it relevant to strategic change?
- What is the goal of “Responsible AI Governance”?
Detailed Answer Key
- Answer: The Development Lifecycle focuses on creating the vision and objectives through planning and synthesis, while the Implementation Lifecycle focuses on translating those objectives into actionable initiatives and managing the transition.
- Explanation: Development is about “what” and “why,” whereas implementation is about “how” and “when.”
- Answer: It creates a clear structure for risk oversight by separating operational management (1st line), risk/compliance oversight (2nd line), and independent audit (3rd line).
- Explanation: This ensures that no single entity is responsible for both executing a strategy and auditing its risks.
- Answer: PESTLE helps organizations analyze external influences (Political, Economic, Social, Technological, Legal, Environmental) that shape and affect their strategy.
- Explanation: It ensures that the strategy is grounded in the reality of the external market and regulatory environment.
- Answer: Scenario planning allows organizations to test their strategy against multiple plausible futures rather than relying on a single, potentially inaccurate forecast.
- Explanation: It increases robustness by identifying “no-regrets” moves that work across various uncertain outcomes.
- Answer: OKR Cascading ensures that high-level strategic objectives are broken down into measurable key results at the portfolio, product, and team levels.
- Explanation: This creates vertical alignment so that every team understands how their work contributes to the organizational vision.
- Answer: Strategic risk involves threats to the organization’s long-term vision and objectives, whereas operational risk involves threats to day-to-day activities and service delivery.
- Explanation: Strategic risks are often external and market-driven, while operational risks are typically internal and process-driven.
- Answer: The components are Direct (setting strategy/policies), Monitor (tracking performance), and Evaluate (reviewing results to trigger adjustments).
- Explanation: This cycle provides the board with a structured way to ensure the organization stays on its strategic course.
- Answer: It refers to managing the integration of multiple service providers as a strategic capability to ensure the entire portfolio delivers unified value.
- Explanation: Strategic SIAM ensures that the “build-buy-partner” ecosystem operates as a single, coherent operating model.
- Answer: Complexity thinking is an approach that acknowledges digital environments as unpredictable systems where small actions have non-linear effects.
- Explanation: It moves strategy away from rigid, predictable planning toward more adaptive, resilient models.
- Answer: To ensure the ethical, compliant, and value-driven adoption of AI within digital products and services.
- Explanation: It addresses board-level concerns such as transparency, accountability, and the mitigation of AI-specific risks.
Open-Ended & Design-Thinking Questions
- Scenario Analysis: You are the Strategic Leader for a global logistics firm. A new “Environmental Regulation” scenario suggests a 300% increase in carbon taxes over five years. How would you adjust your Digital Product Portfolio and Strategic Risk Register to maintain competitive advantage?
- Governance Design: Design a “Three Lines of Defence” architecture for a mid-sized organization that is transitioning from a traditional IT silo model to a product-centric DPSM model. What specific roles would inhabit each line?
- Metric Synthesis: An organization is struggling with “Metric Overload.” Design a simplified Portfolio Dashboard that effectively balances OKRs for a major digital transformation with KPIs for “Business as Usual” service health.
- Investment Prioritization: Using a “Build, Buy, or Partner” mindset, evaluate how a retail company should approach the development of a new AI-driven customer recommendation engine. What strategic factors would lead you to choose “Partner” over “Build”?
- Cultural Transformation: Strategy implementation often fails due to a lack of “Leadership and Communication.” Propose a strategic OCM plan to align a legacy workforce with a new vision of “AI-Augmented Service Delivery.”
Glossary of Key Terms
- DPSM (Digital Product and Service Management): The ITIL 5 evolution from IT management to a unified lifecycle for digital products and services.
- VUCA: An acronym for Volatile, Uncertain, Complex, and Ambiguous; describes the environment in which modern strategies must operate.
- Strategic Risk Register: A tool used to identify and manage risks that could impede the achievement of the organization’s long-term vision.
- Risk Appetite: The amount and type of risk an organization is willing to pursue or retain to meet its objectives.
- Risk Tolerance: The specific, measurable level of variation an organization is willing to accept around its risk appetite.
- Operational Resilience: The strategic ability to absorb, adapt to, and recover from disruptions while maintaining core value delivery.
- DME (Direct, Monitor, Evaluate): The board-level governance framework for overseeing strategy and performance.
- Three Lines of Defence: A governance structure separating operational control, oversight/compliance, and independent audit.
- OKR (Objectives and Key Results): A framework for defining and tracking aspirational, outcome-based strategic goals.
- PESTLE: A framework for analyzing external strategic influences: Political, Economic, Social, Technological, Legal, and Environmental.
- Wardley Mapping: A technique for mapping the value chain to understand the evolution and strategic position of service components.
- SIAM (Service Integration and Management): The practice of managing and integrating multiple service providers to deliver a seamless service portfolio.
- Target Operating Model (TOM): The end-state design of an organization’s capabilities, processes, and people required to execute its strategy.
- Hoshin Kanri: A strategic planning method that ensures the goals of a company are communicated and implemented at every level.
- Responsible AI: A strategic focus on the ethical, transparent, and compliant use of artificial intelligence.
- Digital Ethics: The branch of ethics that focuses on the relationship between the creation, application, and impact of digital technologies.
- Strategy Map: A visual tool used to document the primary strategic goals being pursued by an organization or team.
- Value Stream Metric: A performance measurement focused on the end-to-end flow of value from an initial idea to the final support of a service.
- OCM (Organizational Change Management): The practice of managing the people side of change to achieve a required business outcome.
- Continuous Strategic Improvement: The ongoing effort to refine and adapt the organization’s strategy based on monitoring and evaluation results.
Leaderboard
No scores saved yet. Be the first!
30 Questions — ITIL 5 – Master : Certified ITIL Master - Domain 10 - Strategic Risk, Resilience, and Portfolio Management
Expand any question to reveal the correct answer and explanation.
-
1 An organization is defining its strategic risk appetite for a new AI-driven product line. Which of the following best describes the relationship between risk appetite and risk tolerance in this portfolio context?
Consider the difference between a general philosophical stance and a specific operational constraint.
Risk appetite is the broad amount of risk the organization is willing to accept, while risk tolerance represents the specific boundaries for variations around objectives.
Risk appetite sets the high-level intent, whereas risk tolerance provides the measurable limits for specific initiatives within the portfolio.
-
✗ Risk tolerance is the qualitative desire to innovate, while risk appetite provides the quantitative metrics for board-level reporting.
This reverses the typical relationship, as appetite is often the broader desire and tolerance is the granular constraint.
-
✗ Risk appetite and risk tolerance are synonymous terms used to define the maximum financial loss allowed before a product is decommissioned.
These terms are distinct; appetite refers to the 'pursuit' of risk, whereas tolerance refers to the 'threshold' of acceptable variance.
-
✗ Risk appetite is managed by the Third Line of Defence, while risk tolerance is managed exclusively by the First Line of Defence.
Both concepts are integral to the 'Direct' activity of governance and involve multiple layers of management and oversight.
-
-
2 When developing portfolio-level OKRs (Objectives and Key Results), which metric is most likely to demonstrate 'Value Co-creation' rather than mere operational output?
Focus on the shift from what the provider does to what the customer experiences or achieves.
The increase in the net promoter score (NPS) attributed specifically to integrated digital product features.
This reflects the stakeholder's experience and the perceived value realized through the use of the product.
-
✗ The percentage of service incidents resolved within the first 24 hours of report.
This is an operational output metric focused on efficiency rather than a strategic outcome of co-created value.
-
✗ The total number of AI-enabled automation scripts deployed across the production environment.
While significant, volume-based metrics for tools do not inherently measure the co-creation of value with the customer.
-
✗ A $15\%$ reduction in the cloud infrastructure monthly recurring cost.
This is a cost-efficiency metric which, while important for financial management, does not measure co-created stakeholder outcomes.
-
-
3 A global retailer is using scenario planning to prepare for potential digital disruptions. Which approach is most effective for building 'Operational Resilience' as defined in ITIL (Version 5)?
Think about the distinction between 'being robust' and 'being able to adapt to and recover from shock'.
Designing systems that can natively survive and learn from failure through continuous feedback loops.
Resilience is a primary design goal focusing on the ability of a system to maintain functionality during and after a disturbance.
-
✗ Optimizing existing processes to ensure the highest possible efficiency under current market conditions.
Efficiency optimization often creates fragility; resilience requires the ability to survive volatility, not just optimize for stability.
-
✗ Increasing the capacity of the service desk to handle larger volumes of incident reports during a crisis.
This is a reactive scaling measure rather than a proactive structural design for systemic resilience.
-
✗ Relying on a single, highly stable vendor for all critical digital platform components to minimize complexity.
Single-vendor strategies often introduce strategic risk and lack the diversity needed for high levels of resilience.
-
-
4 In a Volatile, Uncertain, Complex, and Ambiguous (VUCA) environment, an organization identifies a 'Complex' risk. Which strategy is best suited for the Strategic Risk Register?
Recall how strategic decision-making changes when the connection between cause and effect is not immediately obvious.
Using probe-sense-respond cycles to observe emergent patterns before committing to a long-term investment.
Complex environments require experimentation and feedback loops to understand risks that do not have linear solutions.
-
✗ Applying standardized, pre-defined templates from previous successful projects to ensure consistency.
Standardized responses are often ineffective for complex risks where the cause-and-effect relationship is only clear in retrospect.
-
✗ Delegating the risk entirely to a third-party risk management consultancy to avoid internal bias.
Externalizing complex risk does not mitigate the need for the organization to understand the emergent properties of its own portfolio.
-
✗ Ignoring the risk until it becomes 'Simple' or 'Complicated' through the passage of time.
In a VUCA environment, delaying action on complex risks can lead to catastrophic failure or missed strategic opportunities.
-
-
5 An IT Director is reviewing the 'Three Lines of Defence' for portfolio governance. Which activity is specifically the responsibility of the Second Line of Defence?
Focus on the role that provides oversight and standards without being either the 'doer' or the 'independent auditor'.
Establishing the policy framework, monitoring risk compliance, and providing expert advice to product teams.
The Second Line oversees risk and compliance, setting the standards that the First Line must follow.
-
✗ Executing day-to-day risk management and internal controls within the value streams.
Day-to-day execution and control is the primary responsibility of the First Line (operational management).
-
✗ Providing independent assurance to the board regarding the effectiveness of the entire risk management framework.
Independent assurance is the role of the Third Line (internal audit).
-
✗ Directing the organization's mission and purpose while setting the overall risk appetite.
This is a governance function performed by the Board or C-suite, rather than a specific 'line of defence' activity.
-
-
6 Which portfolio-level KPI (Key Performance Indicator) best reflects the ITIL (Version 5) tenet of 'Sustainable Efficiency'?
Look for a measure that balances operational output with environmental or long-term ethical impacts.
The ratio of carbon-aware compute cycles to total data center energy consumption.
This aligns with the tenet of sustainability by measuring the environmental impact of technology operations.
-
✗ The total throughput of the CI/CD pipeline measured in deployments per day.
High throughput does not account for the sustainability or long-term viability of the value being produced.
-
✗ The financial ROI of a digital product within the first six months of launch.
Short-term ROI often ignores the long-term ethical and environmental costs associated with sustainable growth.
-
✗ The employee turnover rate within the DevOps and SRE teams.
While important for organizational health, this is a social/HR metric rather than a direct measure of operational sustainability in tech.
-
-
7 A Strategic Leader is using Wardley Mapping to evaluate the portfolio. A critical digital service component has moved from 'Custom Built' to 'Product'. How should this impact the risk register?
Think about how the 'uniqueness' of a service changes as it matures and what that means for business strategy.
The strategic risk of competitive differentiation increases as the component becomes a commodity.
As components move toward commodity, they no longer provide unique value, shifting the risk toward a loss of strategic edge.
-
✗ The operational risk of failure decreases to zero because products are inherently more stable than custom builds.
Products still carry operational risks, though the nature of the risk shifts from design flaws to vendor dependency.
-
✗ The risk register should be purged of all entries related to this component to reduce administrative toil.
Risk management is continuous; the migration of a component changes the risk profile but does not eliminate it.
-
✗ Financial risk increases because products always require more capital investment than internal custom development.
Products often reduce development costs (OpEx) compared to the high CapEx/OpEx of custom builds, though licensing is a factor.
-
-
8 When prioritizing digital investments, which factor is most critical for ensuring 'Business Alignment' according to the ITIL Strategy Management Model?
Consider the top-down approach of connecting technology spend to 'why' the organization exists.
The alignment of the initiative's expected outcomes with the organization's strategic vision and purpose.
Strategy ensures technology investments are directly linked to business outcomes and long-term value.
-
✗ The technical feasibility of the proposed AI solution as determined by the engineering lead.
Technical feasibility is a constraint, but it does not guarantee that the investment supports the broader business goals.
-
✗ The availability of open-source frameworks to minimize initial software licensing costs.
Cost reduction is a tactical benefit but does not constitute the core of strategic business alignment.
-
✗ The speed at which the feature can be delivered to the market, regardless of its long-term support requirements.
Speed without alignment leads to waste and does not reflect holistic lifecycle thinking.
-
-
9 In the context of 'Resilient Systems', what is the purpose of an 'Error Budget' in a strategic portfolio?
Reflect on how an organization decides when it has 'failed enough' to slow down innovation.
To define the acceptable amount of unreliability that can be tolerated to allow for rapid innovation and change.
Error budgets allow teams to take calculated risks (innovation) as long as they stay within the agreed reliability limits.
-
✗ To provide a financial buffer for paying out SLA penalties to disgruntled customers.
Error budgets are about balancing reliability and innovation, not about budgeting for financial penalties.
-
✗ To track the number of human errors made by the service desk staff for performance reviews.
Error budgets are systemic metrics, whereas tracking individual human error is contrary to a 'blameless' culture.
-
✗ To limit the number of changes that can be made to the production environment in a single quarter.
While it can influence change frequency, its primary goal is to manage the risk-reward tradeoff of stability versus velocity.
-
-
10 Which component of the ITIL Service Value System (SVS) is most responsible for ensuring that digital investments comply with relevant ethics and data regulations?
Identify the element that provides the 'Direct, Monitor, and Evaluate' functions.
Governance
Governance is the means by which the organization is directed and controlled, including compliance and ethical oversight.
-
✗ Management Practices
Practices provide the resources for work, but they operate under the direction set by another SVS component.
-
✗ Service Value Chain
The value chain is an operating model for responding to demand; it executes the governance policies but does not set them.
-
✗ Continual Improvement
Continual improvement focuses on performance alignment but does not serve as the primary control mechanism for ethics.
-
-
11 An organization is facing 'Ambiguity' in a VUCA environment. What is the most appropriate strategic response for portfolio management?
When you don't even know what you don't know, how do you start learning?
Conduct small experiments and prototypes to build a shared understanding of the problem space.
Ambiguity requires exploration and experimentation to clarify the 'unknown unknowns' of a new market or tech.
-
✗ Invest in more precise forecasting tools and historical data analysis to predict the future accurately.
In ambiguous situations, historical data is often irrelevant because the environment itself is poorly understood.
-
✗ Standardize all operating procedures to ensure that everyone follows the same steps regardless of the outcome.
Rigid standardization in an ambiguous environment prevents the learning and adaptation necessary to find a path forward.
-
✗ Wait for a competitor to define the market before committing any resources to the initiative.
Passive waiting can lead to total market exclusion, whereas active experimentation builds internal capability.
-
-
12 When designing a 'Target Operating Model' (TOM) for a digital transformation, which ITIL (Version 5) concept ensures that the model remains 'Human-Centric'?
Recall the Industry 5.0 philosophy of collaboration between man and machine.
Integrating empathy, ethics, and psychological safety into the design of value streams.
Human-centric technology is designed to augment and protect humans, not compete with them.
-
✗ The use of AIOps to replace manual incident management entirely.
Replacing humans entirely is the opposite of augmenting human capability, which is the core of human-centricity.
-
✗ Implementing strict performance monitoring and 24/7 surveillance of remote workers.
This approach often undermines psychological safety and empathy, violating human-centric principles.
-
✗ Prioritizing the speed of the technology stack over the usability of the interface for the staff.
Neglecting usability ignores the human factor in the system, leading to poor adoption and errors.
-
-
13 An organization holds a portfolio of services. One service is highly optimized but lacks 'Resilience.' During a minor cloud outage, the service fails and cannot be restored for 12 hours. What is the likely cause?
Consider why 'lean' processes sometimes fail during unexpected disruptions.
The design focused exclusively on efficiency, removing the 'waste' (redundancy) needed to handle volatility.
Excessive optimization often removes the buffers and diversities required for a system to remain resilient under stress.
-
✗ The service was over-resourced, leading to a complex and unmanageable failure state.
Over-resourcing usually provides more redundancy, not less, although it can increase complexity.
-
✗ The service desk failed to follow the standard operating procedures for incident management.
Resilience is a design and architectural property; no amount of 'procedure following' can fix a brittle system design.
-
✗ The vendor's SLA was too high, leading to a false sense of security among the leadership team.
A false sense of security might delay a response, but it is not the root cause of the design's failure to handle volatility.
-
-
14 In the ITIL Strategy Implementation Lifecycle, 'Reflect' is a critical activity. What is its primary purpose in strategic risk management?
How do we ensure that the next strategy cycle is smarter than the last one?
To analyze outcomes against the original intent to update the strategy and risk appetite for the next cycle.
Reflection ensures that the organization learns from its actions and adjusts its strategic direction based on real-world feedback.
-
✗ To assign blame to the project managers whose initiatives failed to meet the strategic OKRs.
Reflection should be blameless and focused on learning rather than punishment.
-
✗ To mirror the competitor's strategy as closely as possible to minimize market risk.
Reflection is about internal learning and assessment, not blindly mimicking external players.
-
✗ To create a comprehensive report that justifies the current budget spend to the investors.
While reporting is part of it, the 'strategic' purpose of reflection is the continuous adjustment of the strategy itself.
-
-
15 A portfolio manager is evaluating 'Digital Disruption' risks. Which tool provides a visual way to track the maturity of various technologies and their movement toward commodity?
This map uses the axes of 'Value Chain' and 'Evolution'.
Wardley Mapping
Wardley maps specifically show the evolution of components from genesis to commodity against their value chain position.
-
✗ Balanced Scorecard
The Balanced Scorecard tracks performance across four perspectives but does not map the evolution of specific tech components.
-
✗ Hoshin Kanri
Hoshin Kanri is a method for strategy cascading and alignment, not for mapping technological evolution.
-
✗ Business Model Canvas
The canvas outlines how a business creates and delivers value but does not provide a roadmap for tech maturity.
-
-
16 Strategic 'Governance' in ITIL (Version 5) requires board-level monitoring. Which report is most useful for a board to evaluate 'Resilience' across the enterprise?
Board-level reporting should focus on strategic gaps and critical business outcomes.
A dashboard showing the delta between 'Target Operational Resilience' and 'Current Observed Resilience' for critical value streams.
This report allows the board to see if the organization is meeting its resilience goals for its most important services.
-
✗ A list of the top 10 most expensive software licenses currently in use.
Expense tracking is a financial management task, not a measure of systemic resilience.
-
✗ The total number of keystrokes logged by the engineering team during the previous sprint.
Productivity metrics for individuals do not provide insights into the resilience of the organization's services.
-
✗ A chart detailing the average uptime of the corporate website over the last 12 months.
Uptime is a basic service level metric; it does not capture the organization's ability to survive and adapt to volatility.
-
-
17 Which of the following is a 'Human-Centric' approach to using AI in a Strategic Risk Register?
Think of AI as a 'co-pilot' rather than an 'autopilot'.
Using AI to identify subtle risk patterns that humans might miss, then presenting them to a committee for final judgment.
This is an example of AI augmenting human capability while keeping human judgment and empathy in the decision loop.
-
✗ Using an AI algorithm to automatically approve all high-risk investments based on previous success data.
Automating approval of high-risk items removes human judgment and accountability, violating human-centric tenets.
-
✗ Eliminating the risk management team and replacing them with a fully autonomous AI risk agent.
Complete replacement of teams ignores the 'collaboration' aspect of Industry 5.0 and the ITIL (Version 5) tenets.
-
✗ Programming an AI to prioritize financial gain over all environmental and ethical risks identified.
This violates both the sustainability and ethics pillars of the modern framework.
-
-
18 When an organization defines its 'Risk Tolerance', what is it primarily setting?
Think of this as the 'allowable deviation' from the plan.
The measurable boundaries within which the organization can accept variations in its strategic performance.
Risk tolerance provides the operational 'guardrails' for teams to work within without needing further escalation.
-
✗ The maximum amount of money the board is willing to lose on a single project.
While related to loss, tolerance is specifically about the level of variance allowed around a set objective.
-
✗ A list of the only types of risks that the company is allowed to take during a recession.
Tolerance is not a whitelist of risks; it's a measure of the 'volume' or 'variance' of risk allowed.
-
✗ The total number of incidents that can occur before the CEO is fired.
Tolerance is a tool for managing objectives and performance, not a punitive threshold for leadership.
-
-
19 An organization is transitioning from ITIL 4 to ITIL (Version 5). How does the 'Product and Service Lifecycle' affect strategic risk compared to the 'Service Value Chain'?
Think about how 'siloed' thinking versus 'lifecycle' thinking changes where you look for problems.
It provides a more holistic view of risk by integrating discovery, transition, and support into a single flow.
The unified lifecycle encourages end-to-end thinking, identifying risks that occur at the handoffs between traditional silos.
-
✗ It eliminates strategic risk because the lifecycle is shorter and more efficient.
No framework eliminates risk; the lifecycle simply provides a different model for managing it.
-
✗ It increases risk by requiring all products to use the same AI-native code base.
The lifecycle does not mandate specific technologies; it is technology-agnostic.
-
✗ It reduces risk by making the board responsible for all daily operational decisions.
Strategic leadership focuses on direction and framework conditions, not micromanaging operational decisions.
-
-
20 Which of the following describes the 'Investment Prioritization' process in a high-velocity digital portfolio?
Strategic leaders must balance 'running the business', 'changing the business', and 'protecting the business'.
Balancing investments across innovation, maintenance, and risk mitigation using value-stream metrics.
Strategic portfolio management ensures that resources are allocated to sustain long-term value and manage risk across all categories.
-
✗ Prioritizing projects solely based on which department has the highest remaining budget.
Budget availability is a constraint, but strategic prioritization should be based on value and alignment.
-
✗ Executing projects in the order they were received to ensure fairness among all business units.
First-come, first-served is a queueing method, not a strategic prioritization strategy for maximizing value.
-
✗ Investing $100\%$ of all available capital into AI and automation to ensure the organization is 'future-ready'.
Neglecting core maintenance and risk mitigation leads to technical debt and systemic fragility.
-
-
21 A Strategic Leader is setting up 'Portfolio-Level OKRs'. One objective is to 'Reduce Operational Fragility'. What is a relevant Key Result for this objective?
Fragility is the opposite of resilience. How do we prove we are more resilient?
Increase the percentage of critical digital services that can survive the total failure of their primary cloud region.
This is a direct measure of resilience (reducing fragility) by testing the system's ability to maintain operations during shock.
-
✗ Decrease the number of support tickets by $50\%$ through the use of self-service portals.
This measures support efficiency, which may not relate to the underlying fragility of the systems.
-
✗ Achieve a total revenue increase of $12\%$ across all digital product lines.
Revenue is a financial outcome; it is not a direct measure of the technical or operational fragility of the systems.
-
✗ Ensure that $100\%$ of staff have completed their annual compliance training.
This is a compliance output metric and does not measure the resilience of the technology estate.
-
-
22 In ITIL Strategy (Version 5), what does 'Hoshin Kanri' help a Strategic Leader accomplish?
This is a method for 'strategic cascading'.
Aligning the organization's long-term vision with daily activities through a cascade of strategic goals.
Hoshin Kanri is a method for strategy cascading that ensures everyone is pulling in the same direction.
-
✗ Calculating the exact cost of each service incident based on server downtime.
Incident costing is a tactical/operational activity, not the purpose of Hoshin Kanri.
-
✗ Automating the software testing process to improve deployment velocity.
Test automation is a technical management practice, whereas Hoshin Kanri is a strategic planning method.
-
✗ Selecting the most appropriate AI vendor based on a multi-criteria scoring model.
Vendor selection is a sourcing activity, though it may be informed by the goals set through Hoshin Kanri.
-
-
23 An organization is worried about 'Digital Disruption' from a new AI startup. Which strategic activity is most effective for long-term survival?
How do we move from 'denial' to 'integration' when the world changes?
Using scenario planning and 'Build, Buy, or Partner' decisions to adapt the business model to the new reality.
Adaptability and strategic sourcing allow an organization to integrate new technology rather than being crushed by it.
-
✗ Aggressively litigating against the startup for any perceived patent infringements.
Litigation is a defensive tactic that does not address the underlying technological shift causing the disruption.
-
✗ Banning the use of all AI-based tools within the company to maintain 'human-centricity'.
Banning AI ignores the 'human-centric' tenet of using tech to augment humans and leaves the company vulnerable.
-
✗ Doubling down on existing legacy services to ensure that loyal customers feel a sense of stability.
Legacy focus without innovation leads to irrelevance as the market shifts toward new digital experiences.
-
-
24 In the context of 'Strategic Risk', what is the value of a 'Scenario Planning' exercise?
Think about 'stress testing' your strategy against the unknown.
To identify 'blind spots' and test how the current strategy would hold up in different plausible futures.
By exploring diverse scenarios, leaders can build resilience into their strategy and identify risks before they manifest.
-
✗ To create a perfectly accurate prediction of what will happen in the market next year.
Scenario planning is not about prediction; it's about preparation for multiple plausible futures.
-
✗ To determine which employees should be promoted based on their performance in a tabletop simulation.
Simulation performance for individuals is a training/HR concern, not the core strategic purpose of scenario planning.
-
✗ To generate a massive report that satisfies the auditors without actually changing the business direction.
This approach represents a failure of governance, as scenario planning should actively inform and adjust strategy.
-
-
25 A board is concerned about 'ESG' (Environmental, Social, and Governance) reporting. Which ITIL (Version 5) pillar does this most directly support?
Focus on the 'long-term viability' and 'ethical impact' of the organization.
Sustainability
The sustainability tenet encompasses ethical impacts, environmental responsibility, and long-term viability.
-
✗ Human-Centricity
While social factors are human-centric, ESG as a whole is broader, encompassing environment and governance.
-
✗ Resilience
Resilience focuses on surviving volatility, whereas ESG is focused on the broader responsibility and impact of the business.
-
✗ Innovation
Innovation is a driver of value, but ESG is a framework for ensuring that value is created responsibly.
-
-
26 An organization experiences a total failure of its primary digital product. The Strategic Leader notes that this risk was on the 'Risk Register' but was ignored. This is a failure of which activity?
Which function is responsible for 'Directing, Monitoring, and Evaluating' the risk response?
Governance (Monitor and Evaluate)
Governance is responsible for monitoring risks and ensuring that appropriate actions (Evaluate) are taken to address them.
-
✗ Risk Identification
The risk was identified (it was on the register), so the identification phase was successful.
-
✗ Technical Support
Support handles the 'Operate' and 'Deliver' phases, but ignoring a strategic risk is a leadership/governance failure.
-
✗ Digital Strategy Authoring
Authoring involves creating the plan; the failure here was in the ongoing oversight and response to known risks.
-
-
27 A Strategic Leader is evaluating a 'Build, Buy, or Partner' decision for a new AI feature. The risk appetite for this product line is 'Low'. Which option is most likely?
Which option provides the most 'certainty' by leveraging existing, proven capabilities?
Partner: Collaborating with an established, trusted AI provider to leverage their existing, proven platform.
Partnering with a proven provider reduces the risk of genesis-level failure and leverages the partner's expertise.
-
✗ Build: Internally developing the feature from scratch to ensure total control over every line of code.
Building from scratch is high-risk in terms of cost, time-to-market, and the potential for internal failure.
-
✗ Genesis: Hiring a team of researchers to discover a brand-new way to process data using quantum mechanics.
Genesis-level work is the highest possible risk and completely inappropriate for a 'low' risk appetite.
-
✗ Ignore: Deciding not to implement the feature at all to ensure zero risk of failure.
Ignoring digital evolution is a high-risk strategic move that leads to obsolescence.
-
-
28 When defining 'Operational Resilience' metrics, why is 'Uptime' considered an insufficient measure for a strategic board?
Consider what happens when a system is 'up' but performing so poorly that it provides zero value.
Because uptime does not reflect the system's ability to maintain a 'minimum viable service' during a massive degradation.
Resilience is about surviving volatility and maintaining core value, even if the system is not $100\%$ 'up' or 'perfect'.
-
✗ Because uptime is too easy to achieve with modern cloud technologies.
Uptime is not inherently easy; however, it only measures the 'absence of failure' rather than the 'ability to recover'.
-
✗ Because the board is only interested in revenue, and uptime has no correlation with revenue.
Uptime is highly correlated with revenue, but it is too narrow a measure to capture systemic resilience.
-
✗ Because uptime is a binary metric, and the board requires only qualitative narratives.
Boards use both quantitative and qualitative data; the issue with uptime is its lack of depth regarding resilience.
-
-
29 In the ITIL Strategy Management Model, what is the link between the 'Operating Model' and the 'Strategy'?
Think of one as the 'plan' and the other as the 'delivery system'.
The Operating Model is the practical configuration of resources and value streams that implements the Strategy.
The Operating Model (TOM) must be designed to support and realize the strategic goals and vision.
-
✗ The Operating Model defines 'what' the business wants to achieve, while the Strategy defines 'how' the work is done.
This is backwards; Strategy defines the 'what' and 'why', while the Operating Model defines the 'how' (delivery).
-
✗ There is no link; Strategy and Operating Models are managed by separate, disconnected teams.
Disconnect between strategy and operation is a major source of waste and strategic failure.
-
✗ The Operating Model is only for IT teams, while Strategy is only for the C-suite.
ITIL (Version 5) emphasizes organization-wide alignment where strategy and operations are linked across all functions.
-
-
30 A Strategic Leader identifies a 'Strategic Risk' that an AI-driven service might accidentally violate new digital ethics laws. What is the most 'Responsible' first step?
Think about how to build compliance 'into' the system rather than running away from it.
Integrate ethical 'guardrails' and an AI governance framework into the service's lifecycle.
Governance provides the structured guidance needed to adopt AI responsibly, balancing innovation with accountability.
-
✗ Immediately shut down the service and wait for the laws to be clarified by the government.
This is a reactive and potentially wasteful response that might not be necessary if the risk is manageable.
-
✗ Update the Terms of Service to state that the company is not responsible for any ethical violations caused by its AI.
Legal disclaimers do not satisfy the tenet of 'Responsible' technology use or effective strategic governance.
-
✗ Instruct the marketing team to rebrand the AI as 'Legacy Automation' to avoid the new ethics regulations.
Dishonest rebranding does not mitigate the actual risk and violates the core principles of transparency and trust.
-