Courseiva

CRISC Risk Response and Reporting Practice Question

A risk manager is evaluating the effectiveness of a control that requires dual authorization for high-value transactions. The Key Control Indicator (KCI) for this control is the rate of transactions processed without dual authorization (i.e., exception rate). If the acceptable exception rate is less than 1% and the observed rate is 2.5%, what is the most appropriate immediate action?

⚠ Common exam trap

A common mix-up: candidates assume a 2.5% exception rate is still 'low' and choose to accept the risk (Option C), but CRISC emphasizes that any deviation from the acceptable threshold requires investigation and remediation, not automatic acceptance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigate the root cause of the exceptions

The observed exception rate of 2.5% exceeds the acceptable threshold of 1%, indicating a control deficiency. The most appropriate immediate action is to investigate the root cause of the exceptions to determine whether the control is failing due to process gaps, user behavior, or system issues. Root cause analysis (RCA) is a foundational step before any remediation, as it prevents premature redesign or unjustified risk acceptance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Investigate the root cause of the exceptions

    Why this is correct

    The 2.5% exception rate breaches the 1% acceptable threshold, so the control is failing. Root cause investigation identifies why dual authorisation was bypassed before remediation is chosen, ensuring corrective action addresses the actual failure mechanism rather than symptoms.

  • ✗

    Redesign the control immediately

    Why it's wrong here

    Redesigning the control immediately skips the diagnostic step of establishing why dual authorisation was bypassed, so the root cause may persist in the replacement design. It is tempting because redesign is the eventual remedy, and it would be right once investigation confirms the control's design itself is fundamentally flawed.

  • ✗

    Accept the risk since the rate is still low

    Why it's wrong here

    Accepting the risk leaves transactions above the 1% tolerance processed without dual authorisation, so the control is not operating effectively. It is tempting because 2.5% sounds small, but acceptance requires formal risk approval; the immediate action is to investigate the exceptions and remediate the control.

  • ✗

    Increase the acceptable exception rate to 2.5%

    Why it's wrong here

    Changing the threshold without addressing the control deficiency is inappropriate.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.