CRISC IT Risk Assessment Practice Question
A multinational corporation is conducting a risk assessment for its third-party vendors. The risk team has assigned a high inherent risk rating to a vendor that provides critical payroll processing. The vendor has recently provided a SOC 2 Type II report with no exceptions, and the contract includes a right-to-audit clause. The risk practitioner must determine the residual risk rating. Which factor is MOST important in making this determination?
⚠ Common exam trap
The trap here is assuming that any SOC 2 Type II report with no exceptions automatically reduces risk, without verifying that its scope covers the specific services and controls relevant to the risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The scope of the SOC 2 Type II report relative to the payroll processing services.
The scope of the SOC 2 Type II report is the most important factor because it determines whether the independent assurance covers the systems, processes, and trust services criteria relevant to payroll processing. If the report's scope excludes critical controls or infrastructure, the high inherent risk remains largely unaddressed. The right-to-audit clause and vendor characteristics are secondary to understanding whether the controls that matter are actually tested and effective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The scope of the SOC 2 Type II report relative to the payroll processing services.
Why this is correct
The SOC 2 Type II report must cover the specific trust services criteria and processes relevant to payroll processing for the report to reduce residual risk. If the report excludes key systems or controls, the high inherent risk may remain largely unmitigated. Evaluating the scope ensures that the independent assurance actually addresses the risks identified in the assessment, making it the most critical factor.
- ✗
The presence of a right-to-audit clause in the contract.
Why it's wrong here
A right-to-audit clause provides the option to perform an audit in the future, but it does not by itself reduce the current risk. The clause is a contractual safeguard, not evidence that controls are operating effectively today. Without evaluating the actual control environment, such as through the SOC 2 report scope and results, the residual risk rating would be based on potential future action rather than current assurance.
- ✗
The vendor's financial stability and length of time in business.
Why it's wrong here
Financial stability and longevity are relevant to vendor viability but do not directly measure the effectiveness of controls over the payroll data. The residual risk rating should reflect how well the identified risks are mitigated by controls. While financial health can affect the vendor's ability to sustain controls, it is not the most important factor when a SOC 2 Type II report and audit rights are already available.
- ✗
The number of other clients the vendor serves in the same industry.
Why it's wrong here
The vendor's client base may indicate experience and economies of scale, but it does not demonstrate that controls specific to the organization's payroll data are effective. A large client base could also increase the vendor's attack surface or create concentration risk. This factor is not a direct measure of control effectiveness and should not drive the residual risk rating when independent assurance is available.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.