Courseiva
Risk Response and Reporting →mediumMultiple Choice

CRISC Risk Response and Reporting Practice Question

A financial services firm has completed its annual IT risk assessment. The chief risk officer asks the IT risk analyst to classify each identified risk according to the organization's risk taxonomy before any response decisions are made. Which activity should the analyst perform FIRST?

⚠ Common exam trap

The trap here is assuming the most visible or financially quantifiable activity, such as insurance transfer or ALE recalculation, must come first when the foundational step is actually structuring and assigning the risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Map each risk to the relevant business process and asset owner, and assign a consistent risk category and owner.

Classification and ownership assignment come first because every downstream activity, including quantification, treatment selection, transfer, and governance reporting, depends on knowing what each risk is, who owns it, and how it maps to business processes. Establishing a consistent taxonomy and accountable owner creates the structure required for aggregation and defensible risk acceptance at the enterprise level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Recalculate the annualized loss expectancy for every risk using the latest asset valuation data.

    Why it's wrong here

    Quantifying loss expectancy is valuable but depends on knowing which risks belong to which assets and owners. Recalculating ALE before classification produces numbers that cannot be reliably aggregated or compared, and it consumes analysis effort on risks that may later be consolidated into a single enterprise-level entry during taxonomy alignment.

  • ✗

    Immediately transfer the highest-rated risks to the cyber insurance carrier to cap the firm's exposure.

    Why it's wrong here

    Transferring risks before classification and ownership assignment is premature. Insurance placement requires knowing which risks are insurable, what the retention appetite is, and which controls already exist. Acting first on transfer can duplicate coverage, leave non-insurable operational risks untreated, and bypass the risk owner who must accept any residual exposure.

  • ✗

    Publish the complete risk register to the board risk committee for formal acceptance of all identified risks.

    Why it's wrong here

    Reporting to the board before classification and ownership assignment gives the committee an unstructured list they cannot meaningfully accept or prioritize. Board acceptance requires clear risk categories, owners, and evaluated response options; presenting raw findings first undermines governance and forces the committee to defer the decision anyway.

  • ✓

    Map each risk to the relevant business process and asset owner, and assign a consistent risk category and owner.

    Why this is correct

    Structuring risks by business process, asset owner, and consistent taxonomy category creates the traceability needed before any response decision. Without this alignment, the CRO cannot compare risks, delegate ownership, or aggregate exposure across the enterprise, so classification and ownership assignment must precede selecting treatments, calculating residual scores, or reporting to the board.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.