CRISC IT Risk Assessment Practice Question
A risk owner decides to accept a risk because the cost of mitigation exceeds the potential loss, and the risk level is within the organization's risk appetite. What should the risk owner do next?
⚠ Common exam trap
CRISC often tests the importance of formal documentation and sign-off for risk acceptance, but candidates may skip to implementing controls or reassessing, missing the governance step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the risk and obtain formal sign-off
When a risk owner decides to accept a risk because mitigation costs exceed potential loss and the risk is within appetite, the next step is to document the risk and obtain formal sign-off. This ensures accountability, creates an audit trail, and aligns with governance requirements. Acceptance must be an informed, documented decision.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement detective controls to monitor the risk
Why it's wrong here
Acceptance requires no further treatment, so adding detective controls contradicts the decision and consumes resources the cost-benefit comparison already rejected; monitoring is inherent to acceptance, not a new control. Detective controls fit risks being tolerated only if timely detection is needed to limit impact.
- ✗
Reassess the risk using quantitative analysis
Why it's wrong here
Quantitative reassessment is unnecessary once the risk owner has judged the level within appetite and mitigation costlier than the potential loss; the decision is already made, so further analysis delays documentation and monitoring. Quantitative analysis fits comparing treatment options where annualised loss expectancy must be calculated before choosing.
- ✗
Transfer the risk to a third party via insurance
Why it's wrong here
Acceptance already decided, so transferring via insurance contradicts the chosen response and adds cost the owner judged unjustified. Insurance is tempting because it caps catastrophic losses, and would be correct had the owner instead selected risk transfer as the treatment.
- ✓
Document the risk and obtain formal sign-off
Why this is correct
Acceptance is only valid once recorded; the risk owner must document the decision, its rationale and the accepted risk level, then obtain formal sign-off from the appropriate authority. This creates the audit trail demonstrating the acceptance was deliberate and within risk appetite.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.