CRISC IT Risk Assessment Practice Question
A risk practitioner is reviewing the risk register and notices that several risks have not been reassessed in over a year. The business environment has changed significantly due to a new regulation. What is the PRIMARY reason the practitioner should escalate this issue to the risk committee?
⚠ Common exam trap
The trap here is focusing on procedural compliance or individual accountability instead of the substantive risk that outdated assessments may misinform decision-making.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The risk register may no longer reflect the current risk landscape, leading to ineffective risk treatment decisions.
The core issue is that unreviewed risks may no longer be valid after a significant regulatory change. A stale risk register can lead to incorrect treatment priorities and resource allocation. Escalating to the risk committee ensures that reassessment is prioritized and that risk responses are realigned with the new environment, maintaining the effectiveness of risk management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The risk owners have failed to perform their assigned duties, which is a performance management issue.
Why it's wrong here
While risk owners are responsible for reassessment, the issue is broader than individual performance. The new regulation changes the risk context, so even diligent owners may need guidance on updated requirements. Escalation should focus on the need to refresh the risk profile, not on blaming individuals. Performance management is a separate, secondary consideration.
- ✓
The risk register may no longer reflect the current risk landscape, leading to ineffective risk treatment decisions.
Why this is correct
Risk registers must be updated to reflect changes in the internal and external environment. A new regulation can alter likelihood, impact, or risk appetite, making prior assessments obsolete. If the register is stale, treatment plans and resource allocations may be misdirected. Escalation ensures the committee can direct reassessment and realign risk responses with current conditions.
- ✗
The risk committee is required by regulation to meet at least quarterly to review all risks.
Why it's wrong here
While some regulations mandate periodic risk committee meetings, the scenario does not specify such a requirement. The primary concern is the accuracy and relevance of the risk information, not meeting frequency. Escalation is warranted because stale data can lead to poor decisions, not merely because a meeting schedule might be violated.
- ✗
The risk assessment methodology itself is flawed and must be replaced with a quantitative approach.
Why it's wrong here
The scenario does not indicate a flawed methodology, only that risks have not been reassessed. A new regulation may require reassessment, but it does not automatically invalidate the existing methodology. Switching to quantitative methods is a separate decision based on data and needs. The immediate issue is the currency of risk information, not the method used to produce it.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.