Courseiva
Risk Response and MitigationmediumMultiple ChoiceObjective-mapped

Accept Residual Risk Above Tolerance When Cost Prohibitive

After implementing a set of controls, the risk owner calculates the residual risk and finds it is still above the risk tolerance. However, the cost to further reduce the risk exceeds the potential loss. What is the MOST appropriate next step?

Quick Answer

The correct answer is to formally accept the residual risk. This is the most appropriate step because when the cost to further reduce the risk exceeds the potential loss, the principle of cost-benefit analysis dictates that additional mitigation is not economically justified. In risk management, you accept residual risk above tolerance only when the cost of further controls is prohibitive, meaning the expense outweighs the expected benefit of reducing the exposure. On the CRISC exam, this scenario tests your understanding of the risk response decision hierarchy, where acceptance is a valid option after controls are implemented and cost-effectiveness is evaluated. A common trap is choosing to implement more controls out of a false sense of security, but the exam emphasizes that risk acceptance with formal sign-off is the correct governance step when mitigation is not cost-justified. Remember the memory tip: “If the fix costs more than the hit, sign off and accept it.”

⚠ Common exam trap

The CRISC exam often tests the misconception that residual risk must always be reduced to zero or below tolerance regardless of cost, but the correct approach is to accept risk when further mitigation is economically unjustified.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Formally accept the residual risk

When the residual risk remains above the risk tolerance but the cost of further mitigation exceeds the potential loss, the most appropriate step is to formally accept the residual risk. This decision is based on a cost-benefit analysis showing that additional controls are not economically justified. The risk owner documents the acceptance, acknowledging the remaining exposure within the organization's risk appetite framework.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Formally accept the residual risk

    Why this is correct

    Acceptance with sign-off is appropriate when mitigation is too costly.

  • Re-assess the inherent risk

    Why it's wrong here

    Re-assessment does not address the residual risk.

  • Reduce current controls to lower costs

    Why it's wrong here

    This would increase risk.

  • Implement additional controls despite the cost

    Why it's wrong here

    Not cost-effective.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CRISC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. After implementing multiple controls, the residual risk for a new product launch is still slightly above the risk appetite. The risk manager decides to proceed with the launch and monitor the risks regularly. This is:

hard
  • A.Risk Transfer
  • B.Risk Avoidance
  • C.Risk Acceptance
  • D.Risk Mitigation

Why C: The risk manager's decision to proceed with the launch despite residual risk exceeding the risk appetite, while committing to regular monitoring, is the definition of risk acceptance. In IT risk management, this acknowledges that the remaining risk is tolerable for business objectives, and the monitoring plan ensures any escalation is detected early. This is not a passive decision but an active, documented acceptance of the residual risk level.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.