CRISC IT Risk Identification Practice Question
A risk practitioner is facilitating a risk identification workshop for a retail bank's new real-time payments service. Business stakeholders keep proposing controls such as multifactor authentication and transaction limits as 'risks.' Which action BEST keeps the identification phase technically sound?
⚠ Common exam trap
The trap here is treating a control suggestion as a risk entry instead of translating it back into the adverse event the control is intended to prevent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reframe each suggestion by asking what adverse event the control is meant to prevent, and record that adverse event as the risk.
Risk identification captures uncertain events that could affect objectives, while controls are the responses selected later during risk treatment. When stakeholders offer a control, the practitioner should ask what adverse event it is meant to prevent and record that event as the risk. This preserves the register's integrity, allows likelihood and impact to be estimated meaningfully, and keeps the control where it belongs, in treatment planning, so evaluation and appetite comparison remain coherent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Reframe each suggestion by asking what adverse event the control is meant to prevent, and record that adverse event as the risk.
Why this is correct
This is the correct technique. Controls are responses to risk, so the practitioner must surface the underlying event the control addresses. Asking what could go wrong that multifactor authentication or transaction limits would mitigate yields genuine risks such as account takeover or unauthorized high-value transfers. The controls are then captured separately in treatment planning, where they belong. This keeps the identification phase focused on uncertain events affecting objectives and preserves a clean, estimable register for the retail bank.
- ✗
Escalate to the CISO because stakeholders who cannot distinguish controls from risks should not participate in risk identification workshops.
Why it's wrong here
Excluding business stakeholders would undermine the workshop's purpose. CRISC emphasizes that risk identification draws on business and process knowledge, and stakeholders naturally describe concerns in control language because that is how they manage their operations daily. The practitioner's role is to translate those concerns into event-based risk statements, not to remove the people who understand the payment process. Escalation also addresses a facilitation skill gap with authority rather than with technique, leaving the underlying identification problem unresolved.
- ✗
Accept the control suggestions as risks but tag them so they are excluded later during risk evaluation and treatment planning.
Why it's wrong here
Tagging controls as risks and filtering them afterward corrupts the register before it is even built. Risk identification should capture the uncertain events that could affect objectives, not the mechanisms intended to reduce them. If controls are logged as risks, likelihood and impact estimates become meaningless because a control does not have an inherent probability of occurring and causing loss. Downstream evaluation, aggregation, and reporting would then be built on mislabeled entries that cannot be compared against risk appetite.
- ✗
Record both the controls and the underlying events in the register, then let the risk committee decide which entries to retain.
Why it's wrong here
Deferring the distinction to a committee pushes a definitional problem into governance. The register would contain a mixture of events and responses, so likelihood, impact, and inherent versus residual comparisons become incoherent. Committees should adjudicate risk appetite and prioritization, not repair taxonomy errors that the practitioner is equipped to resolve during facilitation. Recording both also inflates the register and can create false dependencies where a control appears as a separate risk requiring its own treatment, which is circular.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.