CRISC IT Risk Assessment Practice Question
A risk manager decides to accept a risk because the cost of controls exceeds the potential loss. Which of the following is required for this risk treatment option?
⚠ Common exam trap
Many exam-takers confuse risk acceptance with risk mitigation or transfer, assuming that any decision involving cost analysis must lead to controls or insurance, but the question explicitly states the cost of controls exceeds the potential loss, making formal acceptance the correct treatment option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Formal sign-off by the risk owner
When a risk manager decides to accept a risk because the cost of controls exceeds the potential loss, the risk treatment option is risk acceptance. This requires formal acknowledgment and sign-off by the risk owner, who is accountable for the risk and must document the decision, typically in a risk register, to ensure governance and auditability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Elimination of the business process
Why it's wrong here
Eliminating the business process is risk avoidance, removing the activity that generates the exposure entirely. Acceptance keeps the process running and retains the risk, so it demands documented sign-off from the accountable risk owner, not termination of the underlying business activity.
- ✗
Transfer of risk via insurance
Why it's wrong here
Insurance transfers the financial consequence to a third party, which is risk transference, not acceptance. Acceptance retains the risk within the organisation, so the requirement is documented approval by risk owners rather than an insurance policy or contractual shift of liability.
- ✗
Implementation of compensating controls
Why it's wrong here
Risk acceptance requires no compensating controls; it is a deliberate decision to retain the risk, documented and approved by the appropriate authority. Compensating controls belong to risk mitigation, where a primary control cannot be applied and an alternative reduces the exposure instead.
- ✓
Formal sign-off by the risk owner
Why this is correct
Risk acceptance demands documented accountability, so formal sign-off by the risk owner satisfies the stem's requirement. The owner holds authority over the affected asset and bears residual loss, making their approval the control that legitimises accepting the risk rather than treating it. Without that signature, acceptance is unowned and unenforceable.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.