easyMultiple Choice
CRISC Practice Question: During a control self-assessment, an operational…
During a control self-assessment, an operational manager reports that a manual review control is performed quarterly instead of monthly as documented. What should the risk practitioner do?
⚠ Common exam trap
Many candidates assume any deviation from documented controls must be immediately corrected or punished, rather than recognizing that the risk practitioner's primary duty is to update the risk register and reassess residual risk based on the actual control state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the control frequency in the risk register and assess residual risk
The risk practitioner must update the control frequency in the risk register to reflect the actual operating reality (quarterly instead of monthly) and then reassess the residual risk. This ensures the risk register remains accurate and the risk exposure is properly evaluated based on the current control effectiveness. Simply accepting the change without documentation (A) or forcing immediate resumption (D) ignores the need for risk reassessment, while escalating for disciplinary action (B) is premature and not the primary risk management action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the change without documentation since risk level is unchanged
Why it's wrong here
Accepting the change without documentation leaves the register, control description and evidence trail misaligned with actual practise, breaking auditability. Informal acceptance suits trivial deviations already reflected in documentation; here the documented monthly frequency must be reconciled through the change process.
- ✗
Escalate the deviation to senior management for disciplinary action
Why it's wrong here
Escalating for disciplinary action treats a control frequency deviation as misconduct before its risk impact is analysed. Senior management escalation fits material, unremediated or deliberately concealed risk; here the manager self-reported the deviation, which calls for analysis and a documented treatment decision.
- ✓
Update the control frequency in the risk register and assess residual risk
Why this is correct
The documented frequency no longer reflects actual practise, so the risk register entry is inaccurate. Recording the quarterly frequency and reassessing residual risk restores alignment between documented controls and operational reality, giving management a true view of the risk exposure created by reduced review cadence.
- ✗
Require the manager to resume monthly reviews immediately
Why it's wrong here
Ordering immediate monthly reinstatement skips assessing why the frequency drifted and whether quarterly review still holds residual risk within tolerance. Directing the control owner is right once the deviation is evaluated and a remediation plan agreed, not as the first response to a self-assessment finding.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.