Courseiva
IT Risk Assessment →hardMultiple Choice

CRISC IT Risk Assessment Practice Question

An organization is considering outsourcing its payroll processing to a third party. The risk assessment shows that the inherent risk of payroll errors is high, but the vendor contract includes liability clauses and the organization obtains cyber insurance. This risk treatment is best described as:

⚠ Common exam trap

CRISC often tests the distinction between risk transfer and risk mitigation, and candidates commonly pick 'risk mitigation' because the scenario mentions a vendor contract — the trap is that liability clauses and insurance shift financial impact (transfer), while mitigation would involve reducing the likelihood or impact of the error itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk transfer

Risk transfer involves shifting the financial impact of a risk to a third party, typically through insurance or contractual liability clauses. Here, the vendor contract includes liability clauses and the organization obtains cyber insurance — both mechanisms shift financial consequences away from the organization. This is the defining characteristic of risk transfer, making it the correct answer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk transfer

    Why this is correct

    Liability clauses and cyber insurance shift the financial consequence of payroll errors to the vendor and insurer, while the organisation retains operational responsibility. This is risk transfer, satisfying the stem's high inherent risk mitigated through contractual and insurance mechanisms rather than avoidance or reduction.

  • ✗

    Risk acceptance

    Why it's wrong here

    Acceptance leaves the risk untreated with no further action; here liability clauses and cyber insurance actively transfer and reduce impact, so the residual risk is deliberately managed rather than retained. Acceptance would be correct where no cost-effective control exists and the organisation consciously tolerates the exposure.

  • ✗

    Risk mitigation

    Why it's wrong here

    Mitigation reduces risk through controls the organisation applies itself, such as validation checks or segregation of duties. This scenario instead shifts financial impact to the vendor via liability clauses and to the insurer via cyber insurance, which is risk transfer, not mitigation of the underlying payroll error likelihood.

  • ✗

    Risk avoidance

    Why it's wrong here

    Outsourcing payroll with contractual liability clauses and cyber insurance retains the activity and transfers some financial impact; the risk is still taken on, so avoidance does not apply. Avoidance means eliminating the exposure entirely, for example by discontinuing payroll processing or bringing it fully in-house.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.