Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A risk manager is categorizing IT risks. Which risk category would a potential fine for violating GDPR be assigned to?

⚠ Common exam trap

CRISC often tests categorization by root cause versus consequence — candidates see 'fine' and pick Financial, ignoring that the originating obligation is regulatory (Compliance).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Compliance

A fine for violating GDPR is a direct consequence of failing to meet a legal/regulatory obligation, which is the definition of compliance risk. Compliance risk encompasses penalties, sanctions, and legal actions arising from non-conformance with laws, regulations, and standards. Although the fine is monetary, its root cause is regulatory non-compliance, so it belongs in the compliance category.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Operational

    Why it's wrong here

    Operational risk covers failures of people, processes and systems, such as outages or processing errors. A GDPR fine stems from breaching a legal or regulatory obligation, which CRISC places in the compliance/legal category. Operational is tempting because the underlying breach may involve process failures, but the fine itself is regulatory.

  • ✗

    Financial

    Why it's wrong here

    A GDPR fine is a monetary penalty, so classifying it as financial describes the loss's form rather than its origin. CRISC categorises by source, and the fine arises from non-compliance with legal requirements, making compliance/legal the correct category. Financial is tempting because the impact is quantifiable in currency.

  • ✗

    Strategic

    Why it's wrong here

    Strategic risk concerns decisions that undermine business objectives, such as entering the wrong market. A GDPR fine results from failing to meet a legal obligation, so compliance/legal is the correct category. Strategic is tempting because non-compliance can damage long-term goals, but the risk event itself is regulatory.

  • ✓

    Compliance

    Why this is correct

    A GDPR fine arises from failing to meet legal and regulatory obligations, so it belongs in the compliance risk category. Compliance risk covers breaches of laws, regulations and standards, distinct from operational, strategic or technology risk categories.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.