CRISC IT Risk Assessment Practice Question
An organization is considering outsourcing its payroll processing to a third party. The risk assessment shows that the inherent risk of payroll errors is high, but the vendor contract includes liability clauses and the organization obtains cyber insurance. This risk treatment is best described as:
⚠ Common exam trap
CRISC often tests the distinction between risk transfer and risk mitigation, and candidates commonly pick 'risk mitigation' because the scenario mentions a vendor contract — the trap is that liability clauses and insurance shift financial impact (transfer), while mitigation would involve reducing the likelihood or impact of the error itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk transfer
Risk transfer involves shifting the financial impact of a risk to a third party, typically through insurance or contractual liability clauses. Here, the vendor contract includes liability clauses and the organization obtains cyber insurance — both mechanisms shift financial consequences away from the organization. This is the defining characteristic of risk transfer, making it the correct answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk transfer
Why this is correct
Liability clauses and cyber insurance shift the financial consequence of payroll errors to the vendor and insurer, while the organisation retains operational responsibility. This is risk transfer, satisfying the stem's high inherent risk mitigated through contractual and insurance mechanisms rather than avoidance or reduction.
- ✗
Risk acceptance
Why it's wrong here
Acceptance leaves the risk untreated with no further action; here liability clauses and cyber insurance actively transfer and reduce impact, so the residual risk is deliberately managed rather than retained. Acceptance would be correct where no cost-effective control exists and the organisation consciously tolerates the exposure.
- ✗
Risk mitigation
Why it's wrong here
Mitigation reduces risk through controls the organisation applies itself, such as validation checks or segregation of duties. This scenario instead shifts financial impact to the vendor via liability clauses and to the insurer via cyber insurance, which is risk transfer, not mitigation of the underlying payroll error likelihood.
- ✗
Risk avoidance
Why it's wrong here
Outsourcing payroll with contractual liability clauses and cyber insurance retains the activity and transfers some financial impact; the risk is still taken on, so avoidance does not apply. Avoidance means eliminating the exposure entirely, for example by discontinuing payroll processing or bringing it fully in-house.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.