mediumMultiple Choice
CRISC Practice Question: A retail company monitors its key risk indicator…
A retail company monitors its key risk indicator (KRI) for credit card transaction fraud. The KRI has exceeded the established threshold for three consecutive days, but the weekly control performance report shows all fraud detection controls operating effectively. What should the risk practitioner do FIRST?
⚠ Common exam trap
Many candidates assume a KRI breach always indicates a control failure, leading them to immediately enhance controls or adjust thresholds, rather than first verifying the data integrity of the KRI itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate the data source of the KRI to ensure accuracy and timeliness.
The KRI breach may be caused by data inaccuracies or delays in the data feed, not by an actual increase in fraud. Investigating the data source ensures the KRI is reliable before taking any further action, aligning with the principle of validating monitoring data before making control decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately enhance the fraud detection controls.
Why it's wrong here
A KRI breaching its threshold while controls test effective signals the risk itself is rising, so the first action is to investigate the indicator and reassess the risk, not alter controls. Enhancing controls is tempting because it feels proactive, but it addresses detection rather than the underlying fraud exposure.
- ✗
Report the KRI breach to the board and recommend risk acceptance.
Why it's wrong here
Escalating to the board skips validation of why the KRI breached while controls report effective, so the practitioner cannot yet recommend acceptance. Reporting to the board suits confirmed, material exposures requiring governance decisions, not an unexplained three-day threshold breach demanding investigation first.
- ✗
Adjust the KRI threshold to align with current control performance.
Why it's wrong here
Raising the threshold suppresses the signal rather than resolving the divergence between the KRI and control performance, hiding a possible detection gap. Threshold tuning is legitimate after investigation confirms the metric is misaligned with the risk appetite, not as a first response to an unexplained breach.
- ✓
Investigate the data source of the KRI to ensure accuracy and timeliness.
Why this is correct
A KRI breaching threshold while controls report effective signals a measurement problem, not a control failure. Verifying the KRI's source data for accuracy and timeliness rules out false positives before escalating or re-tuning thresholds, which is the appropriate first step.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.