CRISC IT Risk Assessment Practice Question
After implementing controls for a high-risk IT process, the residual risk is calculated as medium. The risk owner argues that the controls are not adequate because the inherent risk was critical. Which of the following should be the primary basis for determining control adequacy?
⚠ Common exam trap
CRISC often tests the misconception that controls must eliminate all risk or that inherent risk level dictates control adequacy; candidates should focus on residual risk versus risk appetite and control effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The reduction from inherent risk to residual risk based on control effectiveness
Control adequacy should be determined by the reduction from inherent risk to residual risk based on control effectiveness. The goal of controls is to mitigate risk to an acceptable level; if residual risk is medium and within the organization's risk appetite, the controls may be adequate regardless of the inherent risk being critical. The risk owner's argument that controls are inadequate solely because inherent risk was critical is flawed; what matters is the effectiveness of the controls in reducing risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The number of controls implemented
Why it's wrong here
Counting controls measures effort, not effect; adequacy is judged by whether residual risk falls within the organisation's risk appetite, which medium may already satisfy. It is tempting because more controls intuitively suggest stronger protection, and the count would matter when demonstrating coverage breadth during a compliance audit.
- ✓
The reduction from inherent risk to residual risk based on control effectiveness
Why this is correct
Control adequacy is judged by how far controls reduce inherent risk to residual risk, reflecting actual control effectiveness. A critical inherent rating alone does not prove controls are inadequate; the residual medium result shows measurable reduction, so the owner's argument misreads the basis for adequacy.
- ✗
The cost of controls relative to the asset value
Why it's wrong here
Cost relative to asset value is a budgeting comparison, not an adequacy test; adequacy depends on residual risk against the defined risk appetite, irrespective of spend. It is tempting because cost-benefit analysis legitimately guides control selection, and would be the right basis when justifying whether a proposed control is worth funding.
- ✗
The industry standards for similar processes
Why it's wrong here
Industry standards set a baseline expectation, but adequacy here is determined by residual risk measured against the organisation's risk appetite, which medium may already meet. It is tempting because standards provide defensible benchmarks, and would be the correct basis when assessing whether controls satisfy regulatory or certification obligations.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.