Courseiva
IT Risk Identification →easyMultiple Choice

CRISC IT Risk Identification Practice Question

An organization is categorizing IT risks. Which of the following risk categories would include the risk of regulatory fines due to non-compliance with data protection laws?

⚠ Common exam trap

CRISC often tests whether candidates can separate the cause of a risk from its consequence — the trap is choosing operational risk because a data breach is operational, when the question asks about the risk of regulatory fines, which is compliance risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Compliance risk

Regulatory fines for non-compliance with data protection laws fall squarely under compliance risk, which encompasses the risk of violating laws, regulations, contracts, or standards and the resulting penalties, sanctions, or legal exposure. Data protection regulations such as GDPR or CCPA are compliance obligations, so the associated fine risk is classified as compliance risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Operational risk

    Why it's wrong here

    Operational risk covers failures in people, processes and systems, such as outages or processing errors, not statutory penalties for breaching data protection law. It is tempting because compliance activities are operationally managed, but regulatory exposure is categorised as compliance risk, the correct choice when the loss stems from violating laws or regulations.

  • ✓

    Compliance risk

    Why this is correct

    Regulatory fines for breaching data protection laws arise from failing to meet legal and regulatory obligations, which is precisely the scope of compliance risk. Other categories such as operational or strategic risk do not centre on statutory penalties for non-compliance.

  • ✗

    Financial risk

    Why it's wrong here

    Financial risk addresses losses from market movements, credit defaults, liquidity or currency exposure; a regulatory fine is a consequence, not the originating risk category. It is tempting because fines carry a monetary cost, but the driver is legal non-compliance, which belongs to compliance risk.

  • ✗

    Strategic risk

    Why it's wrong here

    Strategic risk concerns decisions affecting long-term direction, competitive position or business model viability, not penalties for statutory breaches. It is tempting because non-compliance can damage reputation and strategy, but the risk's source is regulatory obligation, which compliance risk captures.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.