CRISC IT Risk Assessment Practice Question
A financial services firm is conducting an IT risk assessment for its customer-facing mobile banking application. The risk team has identified that the application's authentication mechanism relies on a third-party single sign-on (SSO) provider. During a workshop, the risk owner states that the likelihood of a breach is low because the SSO provider has a strong security reputation. However, the risk team notes that no service-level agreement (SLA) exists with the provider. Which risk factor is MOST directly affected by the absence of an SLA, and how should the risk practitioner proceed?
⚠ Common exam trap
The trap here is assuming that a reputable vendor automatically reduces risk without contractual assurances, overlooking the need for an SLA to manage third-party dependency risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The third-party dependency risk is elevated, and the risk practitioner should recommend negotiating an SLA with the SSO provider.
The absence of an SLA with a critical SSO provider introduces third-party dependency risk because there are no contractual guarantees for security, availability, or incident response. The risk practitioner should recognize this as an elevated risk and recommend negotiating an SLA to establish obligations and controls. This is a key part of IT risk assessment, where third-party relationships must be evaluated and managed. The correct answer focuses on the specific risk factor and the appropriate next step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The residual risk of the mobile application is unchanged, so the risk practitioner should focus on internal controls only.
Why it's wrong here
Residual risk is the risk remaining after controls, and the absence of an SLA means third-party controls are not contractually enforced, which can increase residual risk. Focusing only on internal controls ignores the external dependency. The risk practitioner must consider the third-party relationship as part of the overall risk assessment. The correct approach is to address the missing SLA to reduce uncertainty and potential impact.
- ✗
The inherent risk of the SSO provider is reduced, so the risk practitioner should document the risk as acceptable.
Why it's wrong here
The absence of an SLA does not reduce inherent risk; it increases uncertainty and potential impact because there is no contractual guarantee of service levels, security controls, or breach notification. Inherent risk is the risk before controls, and a missing SLA means less control assurance. Documenting the risk as acceptable without further analysis ignores the dependency risk. The practitioner should instead assess the third-party risk and consider risk treatment options.
- ✓
The third-party dependency risk is elevated, and the risk practitioner should recommend negotiating an SLA with the SSO provider.
Why this is correct
The lack of an SLA increases third-party dependency risk because there are no contractual obligations for availability, security, or incident response. The risk practitioner should recommend negotiating an SLA to define performance and security requirements, which helps mitigate the risk. This aligns with CRISC practices for vendor risk management. The other options either wrongly accept the risk or misidentify the risk factor.
- ✗
The risk appetite for the mobile application is exceeded, so the risk practitioner should immediately terminate the SSO contract.
Why it's wrong here
There is no information indicating the risk appetite is exceeded; the scenario only states the risk owner believes likelihood is low. Terminating the contract is a drastic risk treatment that may not be justified without a full assessment. The risk practitioner should first evaluate the risk and recommend proportionate treatment, such as negotiating an SLA. Immediate termination is not the primary action.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.