CRISC Risk Response and Reporting Practice Question
A software company has completed a risk assessment showing that a critical SaaS platform has a residual risk above appetite due to weak vendor access controls. Budget is limited and the remediation will take six months. The CISO must decide how to proceed while the risk remains elevated. Which action BEST aligns with CRISC risk response principles?
⚠ Common exam trap
The trap here is treating a notification letter as risk transfer or lowering a risk score as a response, when real transfer requires contractual or insurance mechanisms and ratings must reflect evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document an interim compensating control, set a remediation timeline, and obtain formal risk acceptance from the accountable business owner until closure.
With residual risk above appetite and remediation requiring six months, the sound approach is to implement interim compensating controls, establish a remediation timeline, and obtain formal acceptance from the accountable business owner. This keeps exposure transparent and owned while respecting business continuity. Suspending service, manipulating ratings, or merely notifying the vendor do not appropriately manage the risk or satisfy governance and reporting expectations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer the risk to the SaaS vendor by sending a notification letter describing the control weaknesses.
Why it's wrong here
Notifying a vendor does not transfer risk; transfer requires a contractual or insurance mechanism that shifts financial consequence. A letter may prompt remediation but leaves the company fully exposed in the meantime. Without an enforceable agreement, the risk remains with the organization, so this action does not resolve the above-appetite condition or satisfy governance requirements.
- ✓
Document an interim compensating control, set a remediation timeline, and obtain formal risk acceptance from the accountable business owner until closure.
Why this is correct
When residual risk exceeds appetite and full remediation cannot be immediate, the appropriate response is to apply interim compensating controls, commit to a timeline, and have the accountable business owner formally accept the remaining risk. This maintains transparency, assigns ownership, and keeps the exposure visible to governance. It aligns with CRISC principles because risk decisions belong to the business owner, not solely to security.
- ✗
Lower the inherent risk rating in the register so that residual risk falls within the approved appetite.
Why it's wrong here
Adjusting the inherent risk rating to force residual risk within appetite is a manipulation of the risk register, not a risk response. It conceals the true exposure from governance and undermines the integrity of risk reporting. CRISC ethics and reporting principles require that ratings reflect evidence and analysis, so changing scores to achieve a desired outcome is indefensible.
- ✗
Suspend all access to the SaaS platform until the vendor access controls are fully remediated.
Why it's wrong here
Suspending access is effectively risk avoidance, but it would halt critical business operations for six months, causing disproportionate disruption. CRISC requires balancing risk against business objectives, and a blanket shutdown ignores the cost of lost revenue and productivity. A more proportionate response uses compensating controls and time-bound acceptance rather than eliminating the service entirely.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.