CRISC Risk Response and Mitigation Practice Question
A multinational bank is subject to GDPR and local data protection laws. The risk practitioner is reviewing a risk treatment plan for a new customer analytics platform that will process personal data across three jurisdictions. The plan proposes to rely on the vendor's standard contractual clauses (SCCs) as the primary control for cross-border data transfers. Which factor is MOST important for the risk practitioner to evaluate when assessing the adequacy of this risk response?
⚠ Common exam trap
The trap here is focusing on technical security controls like encryption or SOC 2 reports when the risk is the legal adequacy of the cross-border transfer mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Whether the vendor's SCCs have been updated to the latest regulatory version and whether a transfer impact assessment has been completed for each jurisdiction.
When SCCs are used as a cross-border transfer control, their adequacy depends on being current with regulatory requirements and being supported by a transfer impact assessment for each destination jurisdiction. The risk practitioner must evaluate legal validity and local law conflicts, not just technical security or retention practices. This ensures the risk response actually mitigates the regulatory risk of unlawful data transfers under GDPR and local laws.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Whether the vendor's SCCs have been updated to the latest regulatory version and whether a transfer impact assessment has been completed for each jurisdiction.
Why this is correct
SCCs are a legal transfer mechanism, but their adequacy depends on the current regulatory version and a jurisdiction-specific transfer impact assessment. The risk practitioner must verify that the clauses are valid and that local laws do not undermine them. This evaluation ensures the control actually mitigates the regulatory and legal risk of cross-border transfers, rather than merely appearing compliant on paper.
- ✗
Whether the analytics platform uses encryption in transit and at rest for all personal data.
Why it's wrong here
Encryption is a technical safeguard that protects data confidentiality, but it does not make an invalid transfer mechanism lawful. GDPR requires a valid legal basis for cross-border transfers, and encryption alone does not satisfy that requirement. The risk practitioner must focus on the legal adequacy of the SCCs and the transfer impact assessment, not just the technical controls protecting the data.
- ✗
Whether the vendor has a SOC 2 Type II report covering the analytics platform's security controls.
Why it's wrong here
A SOC 2 report provides assurance about the vendor's security controls but does not address the legal adequacy of SCCs for cross-border data transfers. The risk in this scenario is regulatory and legal, not purely operational security. While SOC 2 is valuable, it does not evaluate whether the transfer mechanism complies with GDPR or local data protection laws in each jurisdiction.
- ✗
Whether the vendor's data retention policy aligns with the bank's internal records management schedule.
Why it's wrong here
Retention alignment is important for data minimization and compliance, but it does not address the adequacy of SCCs as a cross-border transfer mechanism. The primary risk is that the transfer itself may be unlawful if the SCCs are outdated or undermined by local surveillance laws. Retention policy is a separate compliance consideration and does not validate the legal basis for the transfer.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.