Courseiva
IT Risk Assessment →mediumMultiple Choice

CRISC IT Risk Assessment Practice Question

A risk owner decides to accept a risk because the cost of mitigation exceeds the potential loss, and the risk level is within the organization's risk appetite. What should the risk owner do next?

⚠ Common exam trap

CRISC often tests the importance of formal documentation and sign-off for risk acceptance, but candidates may skip to implementing controls or reassessing, missing the governance step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the risk and obtain formal sign-off

When a risk owner decides to accept a risk because mitigation costs exceed potential loss and the risk is within appetite, the next step is to document the risk and obtain formal sign-off. This ensures accountability, creates an audit trail, and aligns with governance requirements. Acceptance must be an informed, documented decision.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement detective controls to monitor the risk

    Why it's wrong here

    Acceptance requires no further treatment, so adding detective controls contradicts the decision and consumes resources the cost-benefit comparison already rejected; monitoring is inherent to acceptance, not a new control. Detective controls fit risks being tolerated only if timely detection is needed to limit impact.

  • ✗

    Reassess the risk using quantitative analysis

    Why it's wrong here

    Quantitative reassessment is unnecessary once the risk owner has judged the level within appetite and mitigation costlier than the potential loss; the decision is already made, so further analysis delays documentation and monitoring. Quantitative analysis fits comparing treatment options where annualised loss expectancy must be calculated before choosing.

  • ✗

    Transfer the risk to a third party via insurance

    Why it's wrong here

    Acceptance already decided, so transferring via insurance contradicts the chosen response and adds cost the owner judged unjustified. Insurance is tempting because it caps catastrophic losses, and would be correct had the owner instead selected risk transfer as the treatment.

  • ✓

    Document the risk and obtain formal sign-off

    Why this is correct

    Acceptance is only valid once recorded; the risk owner must document the decision, its rationale and the accepted risk level, then obtain formal sign-off from the appropriate authority. This creates the audit trail demonstrating the acceptance was deliberate and within risk appetite.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.