Courseiva
IT Risk Identification →easyMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner is reviewing the organization's risk register and notices that a risk related to a legacy payroll system has been assigned an owner from the IT department. The risk owner is responsible for which of the following?

⚠ Common exam trap

Many candidates confuse the risk owner's accountability for managing the risk with hands-on tasks like implementing controls or performing assessments, which belong to other roles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Managing the risk and ensuring appropriate responses are executed.

The risk owner is accountable for managing a specific risk, including selecting and monitoring risk responses and ensuring the risk stays within acceptable limits. This role is distinct from control implementation, risk assessment, and appetite approval. Clearly defining risk ownership ensures that someone is accountable for each risk and that responses are executed and reported appropriately.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implementing the technical controls to mitigate the risk.

    Why it's wrong here

    Implementing technical controls is typically the responsibility of control owners or IT staff, not the risk owner. The risk owner may ensure that controls are implemented, but they are accountable for the overall management of the risk, not necessarily for hands-on implementation. Confusing these roles can lead to gaps in accountability.

  • ✗

    Performing the annual risk assessment for the payroll system.

    Why it's wrong here

    Performing risk assessments is usually the role of risk practitioners or assessors, not the risk owner. The risk owner may provide input and review results, but the assessment itself is an independent activity. Assigning assessment responsibility to the risk owner could compromise objectivity and create a conflict of interest.

  • ✓

    Managing the risk and ensuring appropriate responses are executed.

    Why this is correct

    The risk owner is accountable for managing the risk, which includes selecting and overseeing risk responses, monitoring the risk, and reporting on its status. For the legacy payroll system, the risk owner would ensure that mitigation, transfer, avoidance, or acceptance decisions are made and carried out, and that the risk remains within acceptable levels.

  • ✗

    Approving the risk appetite statement for the organization.

    Why it's wrong here

    Approving the risk appetite statement is the responsibility of senior management or the board, not an individual risk owner. The risk owner operates within the approved appetite and ensures their specific risk is managed accordingly. Assigning approval authority to a risk owner would undermine governance and dilute executive accountability for risk tolerance.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.