easyMultiple Choice
CRISC Practice Question: Uses control self-assessments (CSAs) as part of…
An organization uses control self-assessments (CSAs) as part of its monitoring program. The results from the latest CSA show that the majority of controls are rated as effective, but an internal audit reveals several control failures in those same areas. What is the MOST likely reason for this discrepancy?
⚠ Common exam trap
Many candidates assume a technical or procedural cause (like scope or documentation errors) rather than recognizing the inherent human bias in self-assessment, which is a classic CRISC concept in the Risk and Control Monitoring and Reporting domain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CSA respondents may have a bias toward reporting favorable results
Control self-assessments (CSAs) rely on the subjective judgment of process owners and operators, who may have a natural tendency to report favorable results to avoid scrutiny or additional work. This self-reporting bias is a well-known limitation of CSAs, leading to an overstatement of control effectiveness. The internal audit, being independent and objective, is more likely to uncover actual control failures, explaining the discrepancy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The CSA scope was narrower than the audit scope
Why it's wrong here
A narrower CSA scope means fewer controls or locations are assessed, so audit testing of unassessed areas naturally finds failures the CSA never examined. This is tempting because scope differences genuinely cause coverage gaps, and it would be the correct choice where the audit sampled processes outside the CSA's defined boundaries.
- ✗
The CSA questionnaire contained documentation errors
Why it's wrong here
Questionnaire documentation errors affect wording or references, not whether assessors honestly judge controls as effective. The discrepancy arises from self-assessment bias or insufficient evidence, not clerical mistakes. Documentation errors would be correct if respondents misread ambiguous questions and rated the wrong control, producing mismatched results.
- ✗
The inherent risk level of the processes decreased after the CSA
Why it's wrong here
Inherent risk is assessed before controls and does not determine whether a self-assessment reports controls as effective. A later risk reduction cannot retroactively make assessors rate failing controls as effective. Inherent risk would be relevant when prioritising which processes to assess, not when explaining an effectiveness-rating discrepancy.
- ✓
CSA respondents may have a bias toward reporting favorable results
Why this is correct
Control self-assessments rely on control owners evaluating their own controls, which introduces a self-assessment bias toward favourable ratings. Respondents may under-report or rationalise weaknesses, so CSA results rate controls effective while independent internal audit testing identifies the actual control failures in those same areas.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.