easyMultiple Choice
CRISC Practice Question: During a control monitoring review, a risk…
During a control monitoring review, a risk analyst discovers that the control owner has not been performing the required monthly reconciliations. What should the analyst do FIRST?
⚠ Common exam trap
It's easy for candidates to confuse 'first step' with 'most impactful action' and choose to escalate or update the register immediately, failing to recognize that understanding the reason for non-performance is a prerequisite for any subsequent action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Contact the control owner to understand the reason for non-performance.
The first step in any control monitoring review is to investigate the root cause of a control failure before taking further action. Contacting the control owner allows the risk analyst to determine whether the non-performance was due to a process issue, resource constraint, or a deliberate decision, which informs the appropriate remediation. Jumping to escalation or documentation without understanding the context could lead to incorrect risk treatment or unnecessary disruption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Contact the control owner to understand the reason for non-performance.
Why this is correct
Contacting the control owner first establishes why the monthly reconciliations were missed before escalating or treating it as a control failure. This satisfies the need to gather accurate evidence, distinguishing a genuine control breakdown from a resourcing or process issue, and informs the appropriate remediation.
- ✗
Escalate to the risk committee for immediate action.
Why it's wrong here
Escalation skips the analyst's own investigation: the risk committee cannot act meaningfully without knowing why reconciliations lapsed, how many periods were missed, and what exposure resulted. Immediate escalation is warranted for confirmed material loss or fraud, not for a first-observed monitoring gap that may reflect a staffing or handover issue.
- ✗
Update the risk register to reflect control deficiency.
Why it's wrong here
Updating the risk register records the deficiency but does not address it. The analyst should first validate and discuss the missed reconciliations with the control owner, confirming whether it is a genuine control failure or a documentation gap, before escalating or amending risk records.
- ✗
Recommend removal of the control as it is not being followed.
Why it's wrong here
Removing a control because it was skipped abandons the risk it addressed, and the analyst lacks authority to approve such removal. The first step is to determine why reconciliations stopped and quantify the exposure. Control retirement is a deliberate decision made only after the underlying risk is reassessed and formally accepted or mitigated elsewhere.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.