Risk response options and strategies: the core decision-making toolkit for anyone who manages business risks. Every organisation faces threats, from a supplier going bankrupt to a cyber attack taking down their website. This concept gives you a structured way to choose what to do about each risk — and CRISC expects you to know exactly when to use which option.
Jump to a section
A simple way to picture Risk Response Options and Strategies: Avoid, Transfer, Mitigate, Accept
A car insurance agent is a professional who helps clients decide how to handle the risks of driving. When a new driver comes in, terrified of getting into an accident, the agent lays out four clear options. First, the driver could avoid the risk entirely by simply not driving. That is the Avoid option, but it means no trips to the beach or the supermarket. Second, the driver could buy a comprehensive insurance policy. That is the Transfer option — the driver pays a monthly premium, and the insurance company takes on the financial risk of a crash. The driver still drives, but the cost of a fender bender becomes the insurer's problem. Third, the agent might suggest taking a defensive driving course and installing a dashcam. That is the Mitigate option — the driver reduces the chance of an accident and the damage if one happens, but still accepts some risk because accidents can still occur. Finally, the driver could decide to drive without insurance at all, paying cash for any repairs out of pocket. That is the Accept option, where the driver fully retains the risk. Just like in business, each choice has a cost and consequences. The agent’s job is to explain those trade-offs so the driver can make an informed decision. This maps precisely to how a risk manager for an IT system evaluates four distinct responses: avoid, transfer, mitigate, or accept.
Risk response is the plan you put in place after you have identified a risk and worked out how big it is. In CRISC, there are exactly four response options: avoid, transfer, mitigate, and accept. Each one is a different way of handling a potential problem. You will hear the mnemonic 'ATMA' in some study circles, which stands for avoid, transfer, mitigate, accept.
Avoid means eliminating the activity that creates the risk. It is the most extreme response. If a new software project is too risky because nobody on the team has the right skills, the organisation could decide not to do the project at all. Avoid does not reduce the risk — it removes it completely. But it also means losing the benefit that the activity would have brought.
Transfer means shifting the financial impact of the risk to another party. The most common example is insurance. A company buys a cyber insurance policy. If a data breach happens, the insurance company pays for the investigation, legal costs, and notification letters. The risk of a breach still exists, but the financial hit is passed to the insurer. Another example is outsourcing — hiring a cloud provider to run your servers. The cloud provider takes on the risk of hardware failure, but the organisation still owns the data and the reputation risk.
Mitigate means taking action to reduce the likelihood or the impact of a risk. This is the most common response. You cannot make a risk go away completely, but you can make it much less dangerous. For example, an organisation might install anti-virus software on all laptops. That does not stop every virus, but it reduces the chance of a successful attack. Mitigation can be technical, like adding a firewall, or procedural, like requiring two people to authorise a large payment.
Accept means acknowledging the risk and consciously deciding to take no action. This is not ignoring the problem. The organisation has evaluated the risk and decided that the cost of fixing it is higher than the potential damage it could cause. For example, a small company might decide not to invest in a backup generator. The risk of a power outage is real, but the cost of a generator is not worth it for a business that only loses a few hundred pounds of work per outage. Acceptance is a deliberate, documented decision.
Choosing the right response depends on the risk appetite of the organisation. Risk appetite is the amount of risk the organisation is willing to take on to achieve its goals. A bank has a very low risk appetite for losing customer money, so it will probably avoid or mitigate those risks heavily. A startup might have a higher appetite and accept risks that a bank would not.
Risk response options are not mutually exclusive. You can mitigate a risk and also transfer part of it. For example, a company installs a security system (mitigate) and buys cyber insurance (transfer). You could even accept a small residual risk after mitigating the rest.
The key idea is that every response has a trade-off. Avoid loses opportunity. Transfer costs a premium. Mitigate costs time and money to implement. Accept leaves you exposed to the full impact. The skill in risk management is balancing these trade-offs to match the organisation's appetite.
Assess the risk
First, evaluate the inherent risk level by considering its likelihood and impact. This step determines if the risk is low, medium, or high. Without an assessment, you cannot choose the right response.
Evaluate risk appetite
Compare the risk level to the organisation's risk appetite. A risk that is acceptable to a startup might be unacceptable to a bank. This comparison directly drives the choice of avoid, transfer, mitigate, or accept.
Identify possible responses
For the identified risk, brainstorm all four response options. For each one, consider the cost, the residual risk left behind, and the impact on business goals. Do not jump to one response too quickly.
Select and document the response
Choose the option (or combination) that best aligns with the risk appetite and cost-benefit analysis. Document the decision in the risk register, including the rationale, the responsible person, and any approvals.
Implement and monitor
Put the response into action. This could mean deploying a firewall (mitigate), signing an insurance contract (transfer), or formalising a decision to accept. Then monitor the residual risk over time to ensure it stays within appetite.
An IT risk manager at a mid-sized e-commerce company discovers that the website's payment processing system has a critical vulnerability. An attacker could steal credit card numbers. The manager follows a structured process to decide how to respond.
First, the manager assesses the risk. The likelihood of an attack is high because the vulnerability is known in hacker forums. The potential impact is also high — fines from regulators, loss of customer trust, and legal fees. The risk score is critical. The manager then presents the four options to the company's leadership. - Avoid: The manager recommends taking the payment page offline entirely until the vulnerability is patched. This stops the risk cold. The downside is that the company stops making sales for a few days. Leadership rejects this because the loss of revenue is too great. - Transfer: The manager checks whether the company's cyber insurance policy covers this scenario. It does, but only for third-party claims. The company still has to pay its own investigation costs. The manager also considers hiring a specialist security firm to handle the forensic investigation if a breach occurs. That would transfer the technical work, but not the legal responsibility. - Mitigate: The manager finds that a simple patch is available from the payment software vendor. The IT team can apply the patch in four hours. The manager also adds web application firewall rules to block common attack patterns. These actions reduce the likelihood of a successful attack from high to low and reduce the impact because the patch closes the main entry point. - Accept: The company could do nothing. The risk is known, but the cost of patching (labour time and potential downtime) is judged to be lower than the expected loss. The manager documents this decision with the signature of the chief financial officer.
In this real scenario, the manager chose to mitigate. The patch was applied, the firewall was updated, and the company also kept its insurance in place as a backstop. The manager then scheduled a follow-up review in one month to ensure the mitigation was effective.
Every step of this process is documented. The risk register — a formal log of risks — now shows the decision, the rationale, and the chosen response. This documentation is critical for auditors and for the CRISC exam, which tests your ability to trace the logic from risk identification through to response.
CRISC tests your understanding of the four risk response options in several specific ways. First, you must be able to identify the correct option for a given scenario. The exam loves to present a situation and ask, 'Which of the following is the BEST risk response?' The answer depends on the organisation's risk appetite and the cost-benefit analysis described in the scenario.
Common traps set by the exam:
Confusing 'mitigate' with 'avoid'. If a scenario describes removing the cause of the risk entirely, the answer is avoid, not mitigate. For example, 'deciding not to enter a new market due to regulatory uncertainty' is avoid. 'Hiring a compliance officer to manage the regulations' is mitigate.
Assuming 'transfer' always means insurance. Transfer can also mean outsourcing, entering a joint venture, or using a contractual clause to shift liability. The key is that someone else takes on the financial consequence.
Thinking 'accept' means ignoring the problem. The exam will test that acceptance requires a conscious, documented decision with management approval. 'We just didn't get around to fixing it' is not acceptance — it's ignorance.
Confusing 'risk response' with 'risk treatment'. In some frameworks these terms are synonyms, but in CRISC the four ATMA options are the official responses.
Key definitions to memorise:
Residual risk: the risk that remains after you have implemented a response. Every response leaves some residual risk. Even avoid leaves the risk of lost opportunity.
Inherent risk: the risk level before any response is applied. The exam will ask you to calculate or compare inherent versus residual risk.
Risk appetite: the amount of risk the organisation is willing to accept. This drives the choice of response.
The exam also tests the order of operations. You must first assess the risk to determine its level. Then choose a response based on that assessment. Then implement the response. Then monitor to ensure the residual risk stays within appetite.
Specific question types:
Scenario-based multiple choice: 'A bank identifies a high-likelihood, high-impact risk of a phishing attack. Which response would BEST align with its low risk appetite?' The correct answer is mitigate (employee training and anti-phishing software) because avoid would stop email entirely, which is impractical.
True/false: 'Acceptance means the organisation has decided to ignore the risk.' The answer is false.
Matching: Match the response to the example. You must know that 'buying insurance' matches 'transfer'.
Memorise the mnemonic ATMA and practise applying it to everyday scenarios, not just IT ones. The exam rewards flexible thinking.
The four risk response options are avoid, transfer, mitigate, and accept — and you must know the exact definition of each for the exam.
Avoid means eliminating the activity that causes the risk; it removes the risk but also removes the opportunity.
Transfer shifts the financial impact to another party (like insurance or outsourcing) but does not transfer responsibility for reputation or operations.
Mitigate reduces the likelihood or impact of a risk but never eliminates it completely; residual risk always remains.
Accept is a deliberate, documented decision to retain the risk because the cost of treatment is higher than the potential loss.
The choice of response must align with the organisation's risk appetite, which defines how much risk it is willing to take on.
These come up on the exam all the time. Here's how to tell them apart.
Avoid
Eliminates the risk by stopping the activity entirely
No residual risk from the original activity, but loses the opportunity
Often used when the risk far outweighs any benefit
Mitigate
Reduces the likelihood or impact but does not stop the activity
Leaves residual risk because the activity continues
Most common response; balances risk and reward
Transfer
Shifts financial liability to another party (insurance, outsourcing)
Cost is the premium or contract fee paid to the third party
The risk event still impacts the organisation operationally
Accept
Retains all liability within the organisation
No cost for treatment, but full exposure to loss if risk occurs
Requires formal documentation and leadership approval
Inherent Risk
Risk level before any response is applied
Reflects the raw, untreated exposure
Used as a baseline to measure the effectiveness of responses
Residual Risk
Risk level after the response is implemented
Reflects the remaining exposure that the organisation must accept
Must be within the organisation's risk appetite
Mistake
Risk acceptance means you stop caring about the risk and let it happen.
Correct
Risk acceptance is a conscious, documented decision that the cost of treating the risk is higher than the potential loss. It must be approved by management, not just ignored.
Beginners hear 'accept' and think 'do nothing'. In reality, it is an active decision requiring formal sign-off.
Mistake
Transferring a risk means you no longer have to worry about it at all.
Correct
Transfer only moves the financial liability. You still own the reputation damage, the operational disruption, and the responsibility for managing the third party (like an insurance company or cloud provider).
People assume transfer is a complete hand-off. It is actually a partnership with shared exposure.
Mistake
Mitigation removes the risk completely.
Correct
Mitigation reduces the likelihood or impact but never eliminates the risk. There is always a residual risk left over.
The word 'mitigate' sounds like 'reduce to zero' to beginners. They confuse it with avoidance.
Mistake
Avoid is always the best response because it eliminates the risk entirely.
Correct
Avoid eliminates the risk but also eliminates the opportunity. It is only the best choice when the risk outweighs any possible benefit. Often, mitigate or transfer are better because they let the organisation still pursue its goals.
New students see risk elimination as the ideal, but they overlook the opportunity cost.
Mistake
You can only use one risk response per risk.
Correct
Organisations commonly combine responses. For example, they might mitigate the risk (install antivirus) and transfer it (buy cyber insurance). The residual risk after combining responses is still assessed.
The four options are taught as individual choices, but in practice they stack. Beginners think it's an either-or decision.
Reveal each answer, then mark whether you got it right. Score 60%+ to unlock the next chapter.
Avoidance removes the risky activity entirely, so the risk disappears. Mitigation keeps the activity but takes steps to reduce the chance of it going wrong or the damage if it does.
Yes. Mitigation reduces the risk to a certain level. When you accept, you are accepting the residual risk that remains after mitigation. This is a common combination.
No. You still manage the relationship with the third party and you still face operational and reputational impact. Only the financial liability is transferred.
Residual risk is the risk that remains after you have applied your chosen response. You must calculate or assess this to prove the response was adequate.
No. Other examples include outsourcing a service, using a fixed-price contract with a vendor, or entering a joint venture where the partner accepts specific liabilities.
When the cost of mitigation exceeds the expected loss from the risk, and the risk is within the organisation's appetite. It is a calculated business decision, not neglect.
You've finished Risk Response Options and Strategies: Avoid, Transfer, Mitigate, Accept. Continue through the CRISC study guide to build a complete picture of the exam.
Done with this chapter?