Courseiva

CRISC Risk Response and Reporting Practice Question

A bank's risk committee is reviewing a proposal to increase the risk appetite threshold for third-party data processing failures from 2 to 5 incidents per year. The head of internal audit objects, noting that three such failures occurred in the last 12 months and one caused a regulatory finding. Which action should the risk committee take FIRST?

⚠ Common exam trap

The trap here is treating risk appetite as a reporting calibration that should match actual performance, rather than a governance boundary that performance must be brought into alignment with.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Evaluate whether existing third-party controls and remediation plans can bring incident frequency within the current threshold before changing the appetite.

Risk appetite defines the level of risk the organization is willing to accept and should guide performance, not be retrofitted to justify it. Before raising the threshold, the committee must determine whether improved third-party controls can reduce failures to within the existing limit. Adjusting appetite to match poor results would normalize the exposure, conflict with the regulatory finding, and weaken governance oversight.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Evaluate whether existing third-party controls and remediation plans can bring incident frequency within the current threshold before changing the appetite.

    Why this is correct

    Changing risk appetite to match current performance inverts the intended relationship: appetite should drive acceptable exposure, not be adjusted to accommodate poor results. The committee should first assess whether control improvements can reduce incident frequency to the existing threshold. Only after determining that the threshold is unachievable or misaligned with strategy should appetite revision be considered, with audit and regulatory implications weighed.

  • ✗

    Immediately approve the new threshold to align reporting with actual performance and close the audit finding.

    Why it's wrong here

    Raising the threshold to match observed failures normalizes unacceptable performance and does not address the root causes behind the incidents. It would also conflict with the regulatory finding, potentially worsening examiner concerns. Risk appetite exists to set boundaries for acceptable exposure; adjusting it primarily to silence an audit issue undermines the governance purpose and leaves third-party risk unmanaged.

  • ✗

    Reject the proposal and take no further action because the current threshold already reflects the board's intent.

    Why it's wrong here

    Rejecting the proposal without analysis ignores the possibility that the threshold is genuinely misaligned with business strategy or market conditions. Good governance requires the committee to evaluate the rationale, control environment, and remediation options before deciding. Simply maintaining the status quo leaves the three recent failures and the regulatory finding unaddressed, which is not a complete risk response.

  • ✗

    Delegate the decision to the third-party management team since they own the vendor relationships.

    Why it's wrong here

    Risk appetite is set at the governance level, not by the operational team managing vendors, because it defines the boundaries within which those teams operate. Delegating the threshold decision would bypass board oversight and could create a conflict of interest, since the vendor management team may prefer looser limits. The committee retains accountability for appetite decisions and should act on the audit input directly.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.