CRISC IT Risk Assessment Practice Question
A newly appointed risk owner is reviewing a risk register entry for an aging payroll application. The entry shows a likelihood rating, an impact rating, an inherent risk score, and a residual risk score, but no owner signature or review date. Which action should the risk practitioner take FIRST to strengthen the register's usefulness for IT risk assessment?
⚠ Common exam trap
The trap here is treating a missing owner as a documentation nuisance rather than the accountability failure that blocks all downstream risk management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confirm the accountable risk owner and establish a review date so the entry has clear ownership and currency.
A register entry is only actionable when someone is accountable and the data is kept current. Confirming the risk owner and setting a review date converts a static record into a managed risk with monitoring and escalation paths. Scoring adjustments, escalations, or field deletions do not remedy the underlying governance gap that the scenario describes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Confirm the accountable risk owner and establish a review date so the entry has clear ownership and currency.
Why this is correct
A risk register entry without an accountable owner or review date cannot support monitoring, treatment decisions, or escalation, because no one is responsible and the data may be stale. Confirming ownership and setting a review cadence is the foundational fix that makes every other register attribute usable. This directly matches the missing fields described in the scenario.
- ✗
Escalate the entry to the audit committee as an unowned high risk requiring immediate remediation funding.
Why it's wrong here
Escalation may eventually be warranted, but the register's immediate deficiency is missing ownership and review metadata, not a proven high rating. Jumping to committee escalation before confirming accountability skips the foundational step of establishing who owns the risk. The scenario gives no indication the score itself is unacceptable.
- ✗
Recompute the inherent and residual scores using a different likelihood and impact scale.
Why it's wrong here
Changing scales does not address the absence of an assigned owner and review date, and it would break comparability with the rest of the register. The scenario's gap is governance metadata, not scoring methodology. Recomputing scores would consume effort without fixing traceability or accountability.
- ✗
Remove the inherent risk score and retain only the residual risk score to simplify reporting.
Why it's wrong here
Deleting the inherent score destroys the ability to see how much risk controls are actually reducing, which is valuable context for treatment decisions. It also leaves the ownership and review gaps untouched. Simplification at the cost of analytical insight does not strengthen the register for risk assessment purposes.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.