CRISC Risk Response and Reporting Practice Question
A healthcare provider has identified a risk that a critical medical imaging system runs on an unsupported operating system. The risk owner determines that the residual risk exceeds the organization's risk appetite, but upgrading the system would cost $2 million and disrupt patient care for several weeks. Which of the following is the MOST appropriate next step?
⚠ Common exam trap
The trap here is treating a compelling business disruption argument as justification for unilateral risk acceptance, when any risk above appetite must be escalated to the authorized governance body for a formal decision.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate the risk to the appropriate governance body with options and recommendations for a risk response decision.
When residual risk exceeds the organization's risk appetite, the risk owner must escalate to the governance body empowered to make risk response decisions. That body can weigh the $2 million upgrade cost and patient care disruption against the security exposure, and choose among options such as phased remediation, compensating controls, or formal risk acceptance. Unilateral acceptance, silent closure, or insurance-only responses bypass required governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer the risk by purchasing cyber insurance and take no other action.
Why it's wrong here
Insurance transfers financial impact but does not address the operational and patient safety risks of an unsupported system. If residual risk still exceeds appetite, transfer alone is insufficient and must still be escalated. The risk owner cannot use insurance to bypass governance decisions about risks above tolerance, especially in a healthcare context with safety implications.
- ✗
Accept the risk because patient care disruption outweighs the security risk.
Why it's wrong here
Accepting a risk that exceeds the organization's stated risk appetite is not appropriate without formal governance approval and documented justification. The risk owner cannot unilaterally accept risk above appetite. Patient care disruption is a serious concern, but it does not eliminate the need to escalate and seek a governed decision on how to respond.
- ✓
Escalate the risk to the appropriate governance body with options and recommendations for a risk response decision.
Why this is correct
When residual risk exceeds the risk appetite, the risk owner must escalate it to the governance body authorized to make risk acceptance or funding decisions. Presenting options, such as phased upgrade, compensating controls, or formal acceptance with mitigation, enables informed decision-making. This aligns with CRISC principles of escalation and governance for risks beyond tolerance.
- ✗
Implement a compensating control and close the risk without further reporting.
Why it's wrong here
Compensating controls may reduce risk, but if residual risk still exceeds the risk appetite, the risk cannot be closed without governance approval. Closing it silently bypasses the escalation requirement and hides a material exposure from decision-makers. The risk should remain open and be reported until the residual risk is formally accepted or reduced within tolerance.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.