easyMultiple Choice
CRISC Practice Question: An external audit finds that a control is not…
An external audit finds that a control is not operating as designed. The auditor recommends corrective action. What should the risk practitioner do FIRST?
⚠ Common exam trap
A common mix-up: candidates confuse the urgency of an audit finding with the need for immediate action, when the correct first step is always to evaluate the risk impact before any remediation or reporting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assess the impact of the control deficiency on residual risk
The risk practitioner must first assess the impact of the control deficiency on residual risk because the finding may not represent a material risk to the organization. Without understanding the severity and likelihood of the risk, any remediation or reporting could be misprioritized. This aligns with the CRISC framework's emphasis on risk-based decision-making before action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement the auditor's recommendation immediately
Why it's wrong here
Implementing the recommendation immediately skips validating whether the control failure reflects a design gap or an operational lapse, and bypasses risk ranking against the organisation's risk appetite. Auditors identify control deficiencies; remediation prioritisation remains a risk management decision. This approach would suit a low-risk, clearly scoped defect where the auditor's finding is already agreed and no competing priorities exist.
- ✗
Develop a remediation plan with the control owner
Why it's wrong here
Remediation planning presumes the finding's risk has been assessed and accepted into the register; doing it first skips validating the finding and determining its risk exposure. Planning is appropriate once the finding is confirmed and prioritised against other risks.
- ✗
Update the risk register with the auditor's finding
Why it's wrong here
Registering the finding records it but does not establish ownership, root cause or treatment, so it cannot be the first action. Updating the register is correct after the finding has been validated and its risk response determined.
- ✓
Assess the impact of the control deficiency on residual risk
Why this is correct
Assessing how the control deficiency affects residual risk establishes whether exposure exceeds tolerance before any remediation is chosen. This determines urgency and priority, ensuring corrective action is proportionate rather than reacting to the audit finding alone.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.