Courseiva
IT Risk Assessment →mediumMultiple Select

CRISC IT Risk Assessment Practice Question

An organization is evaluating whether to accept a risk. Which TWO conditions must be met for risk acceptance to be appropriate?

⚠ Common exam trap

CRISC often tests the confusion between risk acceptance and risk transference — candidates see 'insurer' and think it's part of acceptance, but insurance is a separate treatment option that shifts financial impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The risk owner formally documents and accepts the risk

Risk acceptance is only appropriate when the risk owner formally documents and accepts the risk (B), because accountability for the residual risk must be explicitly acknowledged by the party who owns it, ensuring the decision is authorized and auditable. It is also required that the risk falls within the organization's risk appetite (E), since accepting a risk that exceeds the defined tolerance would violate the risk management framework and require treatment instead. Options A, C, and D do not justify acceptance: transferring risk to an insurer (A) is risk transference, not acceptance; a high but unavoidable risk (C) still needs to be within appetite and formally accepted, and 'unavoidable' alone is not a valid criterion; and having a cost-effective control available (D) argues for risk mitigation rather than acceptance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The risk can be transferred to an insurer

    Why it's wrong here

    Transferring risk to an insurer is risk transference, a distinct treatment that removes the exposure from the organisation, so acceptance is unnecessary. It is tempting because insurance is a legitimate response when a risk exceeds tolerance and the premium is cheaper than the potential loss.

  • ✓

    The risk owner formally documents and accepts the risk

    Why this is correct

    Formal documentation by the risk owner creates the accountability trail that risk acceptance demands: the owner with authority over the affected asset acknowledges the residual risk in writing. This satisfies the stem's requirement that acceptance be a deliberate, authorised decision rather than an unrecorded default, enabling later audit and review.

  • ✗

    The risk is high but unavoidable

    Why it's wrong here

    High severity does not justify acceptance; acceptance requires the risk to fall within tolerance after treatment options are exhausted. It is tempting because unavoidable risks must eventually be lived with, but a high unavoidable risk demands escalation, contingency planning or transfer, not formal acceptance.

  • ✗

    A cost-effective control is available

    Why it's wrong here

    If a cost-effective control exists, implementing it is the appropriate treatment; acceptance applies only when no justified control remains. It is tempting because acceptance is valid when mitigation costs exceed expected loss, but here the control is affordable, so the risk should be reduced instead.

  • ✓

    The risk is within the organization's risk appetite

    Why this is correct

    Risk acceptance is only defensible when the exposure sits inside the tolerance leadership has already defined, so the residual risk must fall within the organisation's stated risk appetite. This satisfies the stem's requirement that acceptance be a deliberate, authority-backed decision rather than an unmanaged gap.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.