Courseiva
IT Risk AssessmenthardMultiple SelectObjective-mapped

CRISC IT Risk Assessment Practice Question

During an IT risk assessment, a risk owner has identified a risk with a high inherent risk score. After reviewing control effectiveness, the residual risk remains medium. The organization decides to accept the residual risk. Which TWO of the following actions should the risk owner take?

⚠ Common exam trap

Many exam-takers confuse risk acceptance with other risk treatment options (transfer, avoid, mitigate) and fail to recognize that after deciding to accept, the key actions are formal sign-off and documentation, not further risk reduction or transfer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Obtain sign-off from the risk owner

The risk owner must formally acknowledge and accept the residual risk after the decision to accept has been made. This sign-off demonstrates that the risk owner is aware of the remaining exposure and agrees to the risk acceptance, which is a key governance step in the risk management process. Without this sign-off, the acceptance is not formally recognized, and accountability remains unclear.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Transfer the risk to a third party

    Why it's wrong here

    Transferring is a different treatment option.

  • Eliminate the activity that creates the risk

    Why it's wrong here

    Eliminating the activity is risk avoidance, not acceptance.

  • Obtain sign-off from the risk owner

    Why this is correct

    The risk owner must formally approve acceptance.

  • Implement additional controls to reduce risk further

    Why it's wrong here

    This would be risk mitigation, not acceptance.

  • Document the risk acceptance formally

    Why this is correct

    Formal documentation is necessary for audit trail and governance.

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.