CRISC IT Risk Identification Practice Question
A risk manager is categorizing IT risks. Which risk category would a potential fine for violating GDPR be assigned to?
⚠ Common exam trap
CRISC often tests categorization by root cause versus consequence — candidates see 'fine' and pick Financial, ignoring that the originating obligation is regulatory (Compliance).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance
A fine for violating GDPR is a direct consequence of failing to meet a legal/regulatory obligation, which is the definition of compliance risk. Compliance risk encompasses penalties, sanctions, and legal actions arising from non-conformance with laws, regulations, and standards. Although the fine is monetary, its root cause is regulatory non-compliance, so it belongs in the compliance category.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Operational
Why it's wrong here
Operational risk covers failures of people, processes and systems, such as outages or processing errors. A GDPR fine stems from breaching a legal or regulatory obligation, which CRISC places in the compliance/legal category. Operational is tempting because the underlying breach may involve process failures, but the fine itself is regulatory.
- ✗
Financial
Why it's wrong here
A GDPR fine is a monetary penalty, so classifying it as financial describes the loss's form rather than its origin. CRISC categorises by source, and the fine arises from non-compliance with legal requirements, making compliance/legal the correct category. Financial is tempting because the impact is quantifiable in currency.
- ✗
Strategic
Why it's wrong here
Strategic risk concerns decisions that undermine business objectives, such as entering the wrong market. A GDPR fine results from failing to meet a legal obligation, so compliance/legal is the correct category. Strategic is tempting because non-compliance can damage long-term goals, but the risk event itself is regulatory.
- ✓
Compliance
Why this is correct
A GDPR fine arises from failing to meet legal and regulatory obligations, so it belongs in the compliance risk category. Compliance risk covers breaches of laws, regulations and standards, distinct from operational, strategic or technology risk categories.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.