Courseiva
IT Risk Identification →easyMultiple Choice

CRISC IT Risk Identification Practice Question

An organization's board has issued a risk appetite statement indicating that the company is willing to accept a moderate level of operational risk but has zero tolerance for compliance violations. This statement primarily defines which of the following?

⚠ Common exam trap

Many exam-takers confuse risk appetite with risk tolerance or risk capacity; candidates often pick 'risk tolerance thresholds' because the statement seems to define limits, but the key is that it expresses willingness, which is appetite.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk appetite

The board's statement explicitly articulates the organization's willingness to accept a moderate level of operational risk while having zero tolerance for compliance violations. This is the definition of risk appetite: the amount and type of risk an organization is willing to pursue or retain in pursuit of its objectives. Risk appetite is set at the strategic level and guides risk tolerance thresholds and risk criteria.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk tolerance thresholds

    Why it's wrong here

    Risk tolerance thresholds quantify acceptable deviation from the risk appetite for specific objectives; they do not express the board's overall willingness to pursue risk. The statement itself is the risk appetite, from which tolerance thresholds are later derived per risk category.

  • ✗

    Risk criteria

    Why it's wrong here

    Risk criteria are the standards, measures and definitions used to evaluate risk significance, not a declaration of how much risk the board will accept. The statement sets the acceptable risk level itself, which is risk appetite; criteria support assessment against that appetite.

  • ✓

    Risk appetite

    Why this is correct

    The statement expresses the board's willingness to accept moderate operational risk while tolerating zero compliance violations, which is the definition of risk appetite: the amount and type of risk an organisation is prepared to pursue or retain. Risk tolerance instead quantifies acceptable deviation around that appetite.

  • ✗

    Risk capacity

    Why it's wrong here

    Risk capacity is the maximum risk an organisation can bear before viability is threatened, an absolute limit rather than a chosen stance. The board's statement expresses deliberate willingness to accept moderate operational risk, which is appetite; capacity would describe the point of ruin.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.