CRISC IT Risk Assessment Practice Question
A retail company is assessing risk for a new customer loyalty application. The risk team determines that the inherent risk is high, then evaluates existing controls and finds that the residual risk is within the organization's risk appetite. The CIO asks what the residual risk rating represents. Which statement BEST describes residual risk in this context?
⚠ Common exam trap
The trap here is conflating residual risk with inherent risk or with control risk, when residual risk specifically means post-control exposure adjusted for control effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The risk that remains after existing controls are applied and their effectiveness is considered.
Residual risk is the exposure that remains once existing controls are applied and their effectiveness is factored in. Because the loyalty application's controls reduce the high inherent risk to a level inside the stated appetite, the residual rating is what the organization actually carries. It drives the decision to accept, mitigate further, transfer, or avoid the risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The risk that the implemented controls themselves will fail to operate as designed.
Why it's wrong here
This describes control risk, the possibility that controls are ineffective or malfunction. While control effectiveness influences residual risk, the two are distinct. Residual risk is the net exposure after accounting for controls; control risk is a contributor to it. Treating them as identical would obscure the actual remaining exposure to the loyalty application.
- ✓
The risk that remains after existing controls are applied and their effectiveness is considered.
Why this is correct
Residual risk is precisely the exposure left after controls are applied, accounting for how well those controls actually work. In this scenario, the loyalty application's high inherent risk is reduced by current controls to a level within appetite. This rating is what the organization actually carries and is the basis for deciding whether further treatment is needed.
- ✗
The total risk exposure before any controls are implemented.
Why it's wrong here
That describes inherent risk, not residual risk. The scenario already established that inherent risk for the loyalty application is high. Residual risk is measured after controls are considered, so confusing the two would lead the CIO to believe the organization faces more exposure than it actually does and could trigger unnecessary additional controls.
- ✗
The maximum plausible loss the organization could suffer from a single risk event.
Why it's wrong here
Maximum plausible loss relates to impact estimation, sometimes called worst-case or single loss expectancy, not residual risk. Residual risk incorporates both likelihood and impact after controls. Equating the two would cause the CIO to focus only on severity and ignore how controls and frequency shape the actual remaining exposure of the loyalty application.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.