Courseiva
easyMultiple Choice

CRISC Practice Question: An external audit finds that a control is not…

An external audit finds that a control is not operating as designed. The auditor recommends corrective action. What should the risk practitioner do FIRST?

⚠ Common exam trap

A common mix-up: candidates confuse the urgency of an audit finding with the need for immediate action, when the correct first step is always to evaluate the risk impact before any remediation or reporting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assess the impact of the control deficiency on residual risk

The risk practitioner must first assess the impact of the control deficiency on residual risk because the finding may not represent a material risk to the organization. Without understanding the severity and likelihood of the risk, any remediation or reporting could be misprioritized. This aligns with the CRISC framework's emphasis on risk-based decision-making before action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement the auditor's recommendation immediately

    Why it's wrong here

    Implementing the recommendation immediately skips validating whether the control failure reflects a design gap or an operational lapse, and bypasses risk ranking against the organisation's risk appetite. Auditors identify control deficiencies; remediation prioritisation remains a risk management decision. This approach would suit a low-risk, clearly scoped defect where the auditor's finding is already agreed and no competing priorities exist.

  • ✗

    Develop a remediation plan with the control owner

    Why it's wrong here

    Remediation planning presumes the finding's risk has been assessed and accepted into the register; doing it first skips validating the finding and determining its risk exposure. Planning is appropriate once the finding is confirmed and prioritised against other risks.

  • ✗

    Update the risk register with the auditor's finding

    Why it's wrong here

    Registering the finding records it but does not establish ownership, root cause or treatment, so it cannot be the first action. Updating the register is correct after the finding has been validated and its risk response determined.

  • ✓

    Assess the impact of the control deficiency on residual risk

    Why this is correct

    Assessing how the control deficiency affects residual risk establishes whether exposure exceeds tolerance before any remediation is chosen. This determines urgency and priority, ensuring corrective action is proportionate rather than reacting to the audit finding alone.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.