Courseiva
IT Risk Assessment →mediumMultiple Select

CRISC IT Risk Assessment Practice Question

An organization is assessing control effectiveness for a key process. Which TWO aspects should be evaluated to determine if a control is effective?

⚠ Common exam trap

The trap is confusing control effectiveness with control compliance or efficiency; candidates may select 'compliance with industry standards' because it sounds important, but effectiveness is about design and operation, not external benchmarks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Operating effectiveness

Operating effectiveness (A) is correct because a control must actually function as intended over time—evidenced by testing that it is applied consistently, by the right people, at the right frequency—to confirm it mitigates the risk in practice. Design adequacy (D) is correct because a control must first be properly designed to address the identified risk at the right point in the process; a well-designed control that operates as intended is the basis for concluding effectiveness. Together, design adequacy and operating effectiveness are the two standard dimensions used when assessing control effectiveness (as in ISACA/COBIT and audit frameworks). Compliance with industry standards (B) is not the criterion for effectiveness—a control can be effective even if it exceeds or differs from a standard, and standards compliance is a separate conformance question. The number of control owners (C) is irrelevant to effectiveness; ownership count says nothing about whether the control mitigates risk. Cost of implementation (E) is a cost-benefit consideration, not a measure of whether the control achieves its objective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Operating effectiveness

    Why this is correct

    Operating effectiveness verifies the control performs consistently as designed over the review period, through testing evidence such as samples, logs or observations. Combined with design adequacy, it establishes whether the control genuinely mitigates the risk within the key process.

  • ✗

    Compliance with industry standards

    Why it's wrong here

    Compliance with industry standards measures alignment with external frameworks, not whether the control actually mitigates the risk it was designed for. It is tempting because certification audits emphasise standards, but effectiveness is judged on design adequacy and operating effectiveness against the organisation's own risk, not third-party benchmarks.

  • ✗

    Number of control owners

    Why it's wrong here

    The number of control owners is an administrative headcount metric, not an indicator that the control mitigates risk as intended. It is tempting because ownership assignment matters for accountability, but that is a governance design concern; effectiveness requires assessing whether the control operates consistently and achieves its risk-reduction objective.

  • ✓

    Design adequacy

    Why this is correct

    Design adequacy confirms the control, as documented and implemented, can actually mitigate the identified risk at the process level. Assessing this alongside operating effectiveness determines whether the control is fit for purpose before testing whether it performs consistently in practise.

  • ✗

    Cost of implementation

    Why it's wrong here

    Cost of implementation is a budgeting consideration, not evidence that a control reduces risk to an acceptable level. It is tempting because cost-benefit analysis accompanies control selection, but that belongs to the risk response decision; effectiveness evaluation examines whether the control operates as designed and achieves its intended risk-reduction objective.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.