CRISC Risk Response and Mitigation Practice Question
An organization is considering outsourcing its IT support to a third-party provider. The risk manager has identified that the provider's data handling practices may not comply with regulatory requirements. Which of the following is the BEST risk response strategy?
⚠ Common exam trap
Watch out — candidates often choose 'mitigate by monitoring' or 'transfer through contract' because they seem proactive, but CRISC expects you to recognize that regulatory compliance risk cannot be effectively transferred or monitored away when the provider's practices are fundamentally non-compliant.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Avoid by keeping IT support in-house
The risk manager has identified that the provider's data handling practices may not comply with regulatory requirements, which represents a high-severity compliance risk that cannot be effectively mitigated through monitoring alone. Avoiding the risk by keeping IT support in-house eliminates the exposure entirely, making it the best response when the risk level exceeds the organization's risk appetite and cannot be reduced to an acceptable level through other strategies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mitigate by regularly monitoring the provider
Why it's wrong here
Monitoring is good but may not fully address regulatory risk.
- ✓
Avoid by keeping IT support in-house
Why this is correct
Avoidance is appropriate when compliance cannot be assured.
- ✗
Transfer the risk through the outsourcing contract
Why it's wrong here
Contract alone may not ensure compliance.
- ✗
Accept the risk because the provider is cheaper
Why it's wrong here
Accepting regulatory risk is not advisable.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.