CRISC Risk Response and Reporting Practice Question
An organization's risk committee reviews a risk heat map showing that a key IT risk has moved from the "high" to "medium" category. However, the associated control's effectiveness has decreased from 95% to 85%. What is the most likely explanation?
⚠ Common exam trap
A common mix-up: candidates assume a decrease in control effectiveness must always increase residual risk, ignoring that a simultaneous decrease in inherent risk can more than compensate, leading to a net reduction in residual risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The inherent risk has decreased due to external factors.
The risk heat map shows a reduction in residual risk from high to medium, yet the control effectiveness dropped from 95% to 85%. This apparent contradiction is best explained by a decrease in inherent risk—the risk before controls are applied. If inherent risk falls (e.g., due to external factors like new regulations or reduced threat activity), the residual risk can decrease even if the control becomes less effective, because the starting risk level is lower.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The control testing frequency was increased.
Why it's wrong here
Increased testing would not reduce risk level independently.
- ✓
The inherent risk has decreased due to external factors.
Why this is correct
A decrease in inherent risk can lower overall risk even if control effectiveness drops.
- ✗
The risk assessment methodology was changed.
Why it's wrong here
There is no evidence of methodology change.
- ✗
The control owner has implemented additional compensating controls.
Why it's wrong here
If compensating controls were added, control effectiveness would likely increase.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.