Courseiva
IT Risk Assessment →mediumMultiple Choice

CRISC IT Risk Assessment Practice Question

A risk manager decides to accept a risk because the cost of controls exceeds the potential loss. Which of the following is required for this risk treatment option?

⚠ Common exam trap

Many exam-takers confuse risk acceptance with risk mitigation or transfer, assuming that any decision involving cost analysis must lead to controls or insurance, but the question explicitly states the cost of controls exceeds the potential loss, making formal acceptance the correct treatment option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Formal sign-off by the risk owner

When a risk manager decides to accept a risk because the cost of controls exceeds the potential loss, the risk treatment option is risk acceptance. This requires formal acknowledgment and sign-off by the risk owner, who is accountable for the risk and must document the decision, typically in a risk register, to ensure governance and auditability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Elimination of the business process

    Why it's wrong here

    Eliminating the business process is risk avoidance, removing the activity that generates the exposure entirely. Acceptance keeps the process running and retains the risk, so it demands documented sign-off from the accountable risk owner, not termination of the underlying business activity.

  • ✗

    Transfer of risk via insurance

    Why it's wrong here

    Insurance transfers the financial consequence to a third party, which is risk transference, not acceptance. Acceptance retains the risk within the organisation, so the requirement is documented approval by risk owners rather than an insurance policy or contractual shift of liability.

  • ✗

    Implementation of compensating controls

    Why it's wrong here

    Risk acceptance requires no compensating controls; it is a deliberate decision to retain the risk, documented and approved by the appropriate authority. Compensating controls belong to risk mitigation, where a primary control cannot be applied and an alternative reduces the exposure instead.

  • ✓

    Formal sign-off by the risk owner

    Why this is correct

    Risk acceptance demands documented accountability, so formal sign-off by the risk owner satisfies the stem's requirement. The owner holds authority over the affected asset and bears residual loss, making their approval the control that legitimises accepting the risk rather than treating it. Without that signature, acceptance is unowned and unenforceable.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.