easyMultiple Choice
First Step After Control Failure: Perform Root Cause Analysis
A risk analyst is reviewing monthly control test results. One control failed testing twice in a row. What is the FIRST step the analyst should take?
Quick Answer
The answer is to perform a root cause analysis of the control failure. This is the correct first step after control failure because it distinguishes between a design flaw—where the control itself is inadequate—and an operational lapse, such as a misapplication or human error. Without this analysis, any subsequent action, like escalating to management or updating the risk register, lacks the necessary context to be effective. On the Certified in Risk and Information Systems Control CRISC exam, this scenario tests your understanding of the risk response lifecycle, where diagnosis must precede communication or remediation. A common trap is jumping to escalation or reporting, which can cause unnecessary alarm or incomplete information. Remember the memory tip: “Analyze before you escalate”—root cause is the foundation for all corrective actions.
⚠ Common exam trap
The trap here is that candidates often jump to reporting or escalation (options A or D) because they confuse operational incident response with risk management, but CRISC emphasizes that understanding the root cause is the prerequisite for any subsequent action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a root cause analysis of the control failure.
The first step when a control fails testing twice in a row is to perform a root cause analysis (RCA) to understand why the failure occurred. Without identifying the underlying cause, any corrective action or reporting would be premature and could lead to ineffective remediation. This aligns with the CRISC focus on proactive risk monitoring and control improvement before escalating or updating risk ratings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Report the failure in the next risk report to management.
Why it's wrong here
Reporting to management is a communication step that follows analysis; the analyst must first determine whether the repeat failure is a genuine control breakdown or a testing artefact. Risk reporting is appropriate once the failure, its cause and its impact have been validated.
- ✓
Perform a root cause analysis of the control failure.
Why this is correct
A repeat failure signals the control itself is flawed, not merely an isolated lapse. Root cause analysis identifies why it failed before redesigning or replacing the control, satisfying the stem's requirement for the first step rather than jumping to remediation.
- ✗
Update the risk register with a higher inherent risk rating.
Why it's wrong here
Inherent risk excludes controls, so a control test failure cannot change it; only the residual risk rating reflects control effectiveness. Updating the register is warranted after the failure is investigated and its effect on residual risk assessed, not as the immediate first action.
- ✗
Escalate the failure to the risk committee immediately.
Why it's wrong here
Escalation is premature: the first step is to investigate why the control failed twice, confirming whether the failure is genuine and identifying the root cause before any committee notification. Escalation suits confirmed, material risk exposures requiring governance decisions, not an unverified repeat test result.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a control monitoring review, a risk analyst discovers that the control owner has not been performing the required monthly reconciliations. What should the analyst do FIRST?
easy- ✓ A.Contact the control owner to understand the reason for non-performance.
- B.Escalate to the risk committee for immediate action.
- C.Update the risk register to reflect control deficiency.
- D.Recommend removal of the control as it is not being followed.
Why A: The first step in any control monitoring review is to investigate the root cause of a control failure before taking further action. Contacting the control owner allows the risk analyst to determine whether the non-performance was due to a process issue, resource constraint, or a deliberate decision, which informs the appropriate remediation. Jumping to escalation or documentation without understanding the context could lead to incorrect risk treatment or unnecessary disruption.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.