After implementing controls, an organization reassesses a risk and finds that the residual risk level exceeds the established risk tolerance. What is the most appropriate next step?
This aligns with risk management process.
Why this answer
When residual risk exceeds the established risk tolerance, the organization must either implement additional controls to reduce the risk further or formally accept the residual risk through management approval. This aligns with the risk treatment decision-making process in ISO 31000 and the CISM framework, where risk acceptance is a management responsibility. Option C correctly identifies these two valid paths.
Exam trap
The CISM exam often tests the misconception that risk assessment methodology changes can resolve residual risk issues, but the trap here is that candidates may choose Option A, thinking a different methodology will yield a more favorable result, when in fact the correct action is to treat the risk through additional controls or formal acceptance.
How to eliminate wrong answers
Option A is wrong because re-assessing with a different methodology does not change the actual risk level; it only changes the measurement, which is a form of risk avoidance through redefinition rather than proper treatment. Option B is wrong because lowering the risk tolerance to match the residual risk is a reactive and inappropriate response that undermines the risk appetite set by the organization; risk tolerance should drive control decisions, not be adjusted to fit uncontrolled risk. Option D is wrong because ignoring residual risk violates the fundamental principle of risk management that requires continuous monitoring and response when risk exceeds tolerance; controls do not absolve the organization from addressing unacceptable residual risk.