Courseiva

CRISC Risk Response and Reporting Practice Question

A multinational retailer's risk register shows a high inherent risk rating for its third-party payment processor. The processor has since obtained an independent SOC 2 Type II report with no exceptions, and the retailer's contract includes a right-to-audit clause. The risk owner proposes lowering the residual risk rating to low. Which factor is MOST important for the risk practitioner to consider before approving the revised rating?

⚠ Common exam trap

The trap here is accepting a clean third-party assurance report at face value without confirming that its scope and testing period cover the services the organization actually depends on.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Whether the SOC 2 report's scope and testing period cover the specific services, systems, and controls the retailer relies on.

Before reducing residual risk based on third-party assurance, the practitioner must confirm that the assurance actually covers the systems, services, and control objectives the organization relies upon. Scope and period alignment determines whether the SOC 2 Type II opinion is relevant evidence. Auditor reputation, audit clause usage, and public breach history may inform judgment but cannot substitute for verifying that the report addresses the specific risk under review.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Whether the SOC 2 report's scope and testing period cover the specific services, systems, and controls the retailer relies on.

    Why this is correct

    A SOC 2 Type II report only provides assurance over the systems, services, and controls within its stated scope and testing period. If the processor's report excludes the payment application or the relevant control objectives, the no-exceptions opinion does not support lowering residual risk. Confirming scope alignment is therefore the most important step before accepting the revised rating.

  • ✗

    Whether the retailer has exercised its right-to-audit clause at least once in the past three years.

    Why it's wrong here

    Exercising a right-to-audit clause can supplement assurance, but its mere exercise does not validate the SOC 2 report's relevance to the retailer's risk. The clause is a contractual capability, not evidence that the processor's controls are effective for the services the retailer depends on. Recency of exercising the clause is secondary to confirming report scope.

  • ✗

    Whether the processor's SOC 2 report was issued by a well-known audit firm with a strong market reputation.

    Why it's wrong here

    The reputation of the audit firm does not determine whether the report addresses the retailer's specific reliance on the processor's systems and controls. A prestigious firm can still issue a report with a scope that omits critical payment services. Auditor brand is a weak substitute for verifying that the report's coverage actually matches the risk being reassessed.

  • ✗

    Whether the processor has publicly announced any data breaches during the current fiscal year.

    Why it's wrong here

    Absence of a publicly announced breach does not prove that controls are effective; many incidents are never disclosed publicly, and the SOC 2 report itself is the primary assurance artifact. Public breach status also does not address whether the report's scope covers the retailer's services. This factor is relevant background but not the most important consideration for approving the revised rating.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.