CRISC IT Risk Identification Practice Question
A financial services firm is identifying risks for a new mobile banking feature that will rely on a third-party identity verification provider. The vendor has provided a SOC 2 Type II report, but the firm has not yet reviewed it. Which of the following BEST describes how the firm should treat the vendor-related risk during identification?
⚠ Common exam trap
The trap here is treating a SOC 2 Type II report as proof that vendor risk can be excluded from the register rather than as evidence that informs an assessment the firm still owns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Record the vendor dependency as a risk and assess it after reviewing the report's scope, period, and exceptions.
Third-party dependencies must be identified and recorded regardless of the assurance a vendor provides. The firm should log the dependency and then assess it using the SOC 2 Type II report's scope, coverage period, complementary user entity controls, and exceptions, so that residual risk is judged realistically. Assurance evidence informs the assessment; it does not remove the dependency from the register or transfer the firm's accountability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Record the vendor dependency as a risk and assess it after reviewing the report's scope, period, and exceptions.
Why this is correct
Third-party dependencies are a recognized risk source that must appear in the risk register regardless of vendor assurances. Recording the dependency and then evaluating the SOC 2 Type II report's scope, coverage period, complementary user entity controls, and noted exceptions allows the firm to judge residual risk realistically. This keeps accountability with the firm while using vendor evidence to inform, not replace, its own risk assessment.
- ✗
Exclude vendor risk from the register because the SOC 2 Type II report demonstrates adequate controls.
Why it's wrong here
A SOC 2 Type II report provides assurance about controls at a point in time and within a defined scope, but it does not eliminate risk or transfer accountability. The firm remains responsible for the data and services it exposes. Excluding the vendor from the risk register before reviewing the report would create a blind spot for integration risks, availability dependencies, and contractual gaps that the report may not address.
- ✗
Transfer the risk entirely to the vendor by referencing the SOC 2 report in the contract.
Why it's wrong here
Risk transfer through contract or insurance shifts some financial consequence but never the accountability for customer data, regulatory compliance, or service continuity. Referencing a report in a contract does not make the vendor responsible for the firm's own obligations, and the report may cover a narrower scope than the service being consumed. The firm must still identify, assess, and monitor the dependency in its own risk register.
- ✗
Defer identification until the vendor completes a penetration test of the identity verification platform.
Why it's wrong here
Deferring identification until additional evidence exists delays the entire risk process and leaves the dependency unmanaged while the mobile feature is designed and built. Identification should capture the dependency now, using currently available information, and the assessment can be refined as further evidence such as penetration test results arrives. Waiting for perfect evidence before recording a known dependency is a common cause of late, costly remediation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.