Courseiva

CRISC Risk Response and Mitigation Practice Question

A multinational corporation has adopted a risk mitigation strategy for its key suppliers by requiring them to maintain ISO 27001 certification. During an audit, the risk manager discovers that one critical supplier lost its certification six months ago but did not report it, as contractually required. The supplier still has adequate security controls in place, and the relationship is strategically important. The CEO wants to avoid contract termination. What is the MOST appropriate risk response?

⚠ Common exam trap

CRISC often tests the misconception that risk acceptance is always acceptable if controls are present, but the key is that contractual non-compliance and loss of independent assurance require a formal response; candidates may overlook the need to address the root cause through a corrective action plan.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Issue a corrective action plan requiring the supplier to regain certification within three months, with monthly progress reviews.

The most appropriate risk response is to issue a corrective action plan with a deadline and monitoring, because it directly addresses the control gap (lapsed certification) while preserving the strategic relationship. ISO 27001 certification is a contractual requirement and a key risk mitigation control; its loss increases risk even if other controls exist. A corrective action plan is a targeted risk treatment that restores compliance and provides assurance through monthly reviews, aligning with CRISC's emphasis on balancing risk and business objectives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Issue a corrective action plan requiring the supplier to regain certification within three months, with monthly progress reviews.

    Why this is correct

    A corrective action plan with monthly reviews addresses the contractual breach and certification lapse while preserving the strategic relationship, satisfying the CEO's wish to avoid termination. It imposes measurable remediation deadlines rather than accepting or transferring the supplier risk outright.

  • ✗

    Transfer the risk to the supplier's cyber liability insurance policy.

    Why it's wrong here

    Insurance transfers financial loss only; it cannot transfer the supplier's obligation to hold ISO 27001 certification or the reporting failure. Transfer is tempting because liability shifts, but the compliance requirement remains with the organisation and supplier regardless of any policy payout.

  • ✗

    Accept the risk because the supplier still has effective controls, and update the risk register.

    Why it's wrong here

    Accepting the risk leaves the supplier non-compliant with the mandatory ISO 27001 requirement and unaddressed reporting breach, so the mitigation strategy is not maintained. Acceptance is tempting because controls remain effective, but it applies when residual risk is tolerable, not when a contractual control obligation has failed.

  • ✗

    Terminate the contract immediately and find an alternative supplier.

    Why it's wrong here

    Immediate termination ignores the adequate controls, strategic importance and the CEO's position, and treats a contractual breach as an automatic exit. Termination is tempting as the strictest enforcement of the ISO 27001 requirement, but the scenario calls for a proportionate response rather than severing the relationship outright.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.