CRISC IT Risk Assessment Practice Question
During an IT risk assessment, a risk owner has identified a risk with a high inherent risk score. After reviewing control effectiveness, the residual risk remains medium. The organization decides to accept the residual risk. Which TWO of the following actions should the risk owner take?
⚠ Common exam trap
Many exam-takers confuse risk acceptance with other risk treatment options (transfer, avoid, mitigate) and fail to recognize that after deciding to accept, the key actions are formal sign-off and documentation, not further risk reduction or transfer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Obtain sign-off from the risk owner
The risk owner must formally acknowledge and accept the residual risk after the decision to accept has been made. This sign-off demonstrates that the risk owner is aware of the remaining exposure and agrees to the risk acceptance, which is a key governance step in the risk management process. Without this sign-off, the acceptance is not formally recognized, and accountability remains unclear.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer the risk to a third party
Why it's wrong here
Transferring is a different treatment option.
- ✗
Eliminate the activity that creates the risk
Why it's wrong here
Eliminating the activity is risk avoidance, not acceptance.
- ✓
Obtain sign-off from the risk owner
Why this is correct
The risk owner must formally approve acceptance.
- ✗
Implement additional controls to reduce risk further
Why it's wrong here
This would be risk mitigation, not acceptance.
- ✓
Document the risk acceptance formally
Why this is correct
Formal documentation is necessary for audit trail and governance.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.