CRISC IT Risk Identification Practice Question
An organization's board has issued a risk appetite statement indicating that the company is willing to accept a moderate level of operational risk but has zero tolerance for compliance violations. This statement primarily defines which of the following?
⚠ Common exam trap
Many exam-takers confuse risk appetite with risk tolerance or risk capacity; candidates often pick 'risk tolerance thresholds' because the statement seems to define limits, but the key is that it expresses willingness, which is appetite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk appetite
The board's statement explicitly articulates the organization's willingness to accept a moderate level of operational risk while having zero tolerance for compliance violations. This is the definition of risk appetite: the amount and type of risk an organization is willing to pursue or retain in pursuit of its objectives. Risk appetite is set at the strategic level and guides risk tolerance thresholds and risk criteria.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk tolerance thresholds
Why it's wrong here
Risk tolerance thresholds quantify acceptable deviation from the risk appetite for specific objectives; they do not express the board's overall willingness to pursue risk. The statement itself is the risk appetite, from which tolerance thresholds are later derived per risk category.
- ✗
Risk criteria
Why it's wrong here
Risk criteria are the standards, measures and definitions used to evaluate risk significance, not a declaration of how much risk the board will accept. The statement sets the acceptable risk level itself, which is risk appetite; criteria support assessment against that appetite.
- ✓
Risk appetite
Why this is correct
The statement expresses the board's willingness to accept moderate operational risk while tolerating zero compliance violations, which is the definition of risk appetite: the amount and type of risk an organisation is prepared to pursue or retain. Risk tolerance instead quantifies acceptable deviation around that appetite.
- ✗
Risk capacity
Why it's wrong here
Risk capacity is the maximum risk an organisation can bear before viability is threatened, an absolute limit rather than a chosen stance. The board's statement expresses deliberate willingness to accept moderate operational risk, which is appetite; capacity would describe the point of ruin.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.