CRISC Risk Response and Reporting Practice Question
A financial services firm has completed a risk assessment and determined that the residual risk for its online banking platform exceeds the board-approved risk appetite. The CISO must recommend risk response options to the risk committee. Which TWO of the following are appropriate risk response actions? (Choose two.)
⚠ Common exam trap
The trap here is treating risk acceptance as a default when exposure exceeds appetite, when acceptance above tolerance requires explicit authority the risk owner does not hold.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement additional compensating controls to reduce the residual risk to within appetite
When residual risk exceeds appetite, the risk owner must choose from the recognized response set: mitigate, transfer, avoid, or accept with proper authority. Applying compensating controls reduces the exposure, and transferring part of the financial consequence through insurance addresses what remains. Accepting without authority, recalculating assumptions to change the rating, and deleting the risk from the register are not legitimate responses because they alter the record rather than the risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement additional compensating controls to reduce the residual risk to within appetite
Why this is correct
Applying additional compensating controls is the risk mitigation response, directly lowering likelihood or impact so residual risk falls back within the approved appetite. Since the committee has already determined the exposure is unacceptable, reducing it through controls is the primary and most defensible action. It also preserves the business capability while bringing exposure into alignment with the tolerance the board has formally set.
- ✗
Remove the platform from the risk register so it no longer appears as an exception in committee reporting
Why it's wrong here
Removing an identified risk from the register suppresses information rather than managing the exposure, and it defeats the purpose of exception reporting that alerts the committee to appetite breaches. The risk still exists operationally whether or not it is recorded. This action would also violate the traceability expectations of the risk management framework and could expose the firm to regulatory criticism.
- ✓
Transfer a portion of the exposure through a cyber insurance policy and document the retained risk
Why this is correct
Risk transfer shifts part of the financial consequence to a third party, and cyber insurance is a recognized transfer mechanism for residual exposure that cannot be economically reduced further. Documenting the retained portion keeps the committee aware of what remains after transfer. Transfer does not eliminate the risk, so it must be paired with clear disclosure of the deductible, coverage limits, and exclusions that still leave exposure with the firm.
- ✗
Recalculate the annualized loss expectancy using a lower single loss expectancy to bring the rating within tolerance
Why it's wrong here
Adjusting loss expectancy assumptions to change the rating is manipulating the assessment rather than responding to the risk. The underlying exposure has not changed, so the residual risk remains above appetite regardless of the recalculated figure. Altering inputs to achieve a desired outcome undermines the integrity of the risk process and would mislead the committee about the true exposure.
- ✗
Accept the residual risk without further action because the platform generates significant revenue
Why it's wrong here
Acceptance is a valid response only when the risk owner has authority to accept exposure above appetite, which the scenario rules out because the board set the appetite and the exposure exceeds it. Revenue significance is a business justification, not an acceptance authority. Choosing acceptance here would bypass governance and leave an unmanaged gap between actual and approved risk tolerance.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.