easyMultiple ChoiceObjective-mapped
First Step After Control Failure: Perform Root Cause Analysis
A risk analyst is reviewing monthly control test results. One control failed testing twice in a row. What is the FIRST step the analyst should take?
Quick Answer
The answer is to perform a root cause analysis of the control failure. This is the correct first step after control failure because it distinguishes between a design flaw—where the control itself is inadequate—and an operational lapse, such as a misapplication or human error. Without this analysis, any subsequent action, like escalating to management or updating the risk register, lacks the necessary context to be effective. On the Certified in Risk and Information Systems Control CRISC exam, this scenario tests your understanding of the risk response lifecycle, where diagnosis must precede communication or remediation. A common trap is jumping to escalation or reporting, which can cause unnecessary alarm or incomplete information. Remember the memory tip: “Analyze before you escalate”—root cause is the foundation for all corrective actions.
⚠ Common exam trap
The trap here is that candidates often jump to reporting or escalation (options A or D) because they confuse operational incident response with risk management, but CRISC emphasizes that understanding the root cause is the prerequisite for any subsequent action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a root cause analysis of the control failure.
The first step when a control fails testing twice in a row is to perform a root cause analysis (RCA) to understand why the failure occurred. Without identifying the underlying cause, any corrective action or reporting would be premature and could lead to ineffective remediation. This aligns with the CRISC focus on proactive risk monitoring and control improvement before escalating or updating risk ratings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Report the failure in the next risk report to management.
Why it's wrong here
Reporting should include root cause and remediation plan.
- ✓
Perform a root cause analysis of the control failure.
Why this is correct
Root cause analysis is essential before taking further action.
- ✗
Update the risk register with a higher inherent risk rating.
Why it's wrong here
Risk rating changes should be based on analysis.
- ✗
Escalate the failure to the risk committee immediately.
Why it's wrong here
Escalation without analysis may be premature.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a control monitoring review, a risk analyst discovers that the control owner has not been performing the required monthly reconciliations. What should the analyst do FIRST?
easy- ✓ A.Contact the control owner to understand the reason for non-performance.
- B.Escalate to the risk committee for immediate action.
- C.Update the risk register to reflect control deficiency.
- D.Recommend removal of the control as it is not being followed.
Why A: The first step in any control monitoring review is to investigate the root cause of a control failure before taking further action. Contacting the control owner allows the risk analyst to determine whether the non-performance was due to a process issue, resource constraint, or a deliberate decision, which informs the appropriate remediation. Jumping to escalation or documentation without understanding the context could lead to incorrect risk treatment or unnecessary disruption.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.