hardMultiple ChoiceObjective-mapped
KRI Green but Control Testing Fails? Investigate the KRI Calculation Methodology First
A company monitors key risk indicators (KRIs) using a dashboard. The risk manager notices that a KRI has a green status but the underlying control testing shows a high failure rate. What action should the risk manager take FIRST?
Quick Answer
The answer is to investigate the KRI calculation methodology first. This is correct because a green KRI status paired with a high control failure rate signals a fundamental disconnect in the risk measurement framework; the KRI may be using stale data, incorrect thresholds, or a flawed aggregation formula that masks the true risk exposure. On the CRISC exam, this scenario tests your understanding of the relationship between KRIs and control testing, emphasizing that KRIs are leading indicators that must be validated against actual control performance. A common trap is to immediately adjust the KRI threshold or escalate the issue, but the correct first step is always root cause analysis of the metric itself. Remember the memory tip: “Green KRI, red control? Check the math before you scroll.”
⚠ Common exam trap
Candidates often assume a green KRI means the risk is low and immediately focus on fixing the control (Option D) or adjusting the threshold (Option B), rather than recognizing that the KRI itself may be flawed and requires investigation first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate the KRI calculation methodology
The KRI showing green while the underlying control has a high failure rate indicates a misalignment between the KRI and the actual control effectiveness. The first step is to investigate the KRI calculation methodology to determine if the KRI is measuring the wrong metric, using stale data, or has an incorrect threshold. Only after understanding why the KRI is misleading can the risk manager take appropriate corrective action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Escalate to the risk committee
Why it's wrong here
Escalation without analysis does not provide useful information for decision-making.
- ✗
Change the KRI threshold to amber
Why it's wrong here
Changing thresholds without investigation could mask the real problem.
- ✓
Investigate the KRI calculation methodology
Why this is correct
The KRI might be using incorrect data or outdated baselines.
- ✗
Re-test the control
Why it's wrong here
Re-testing assumes the control test is wrong, but the issue may be the KRI.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A technology company has implemented a risk and control monitoring program for its software development lifecycle. The program includes key risk indicators (KRIs) such as number of critical bugs found in production, code review coverage, and time to patch vulnerabilities. After six months, the risk committee noticed that the KRI for code review coverage is consistently green (within threshold), but the number of critical bugs in production remains high. The risk manager suspects a disconnect between the KRI and actual risk. What should the risk manager do FIRST?
easy- A.Implement additional testing controls to catch bugs before production.
- B.Reduce the code review coverage target to lower the risk appetite.
- ✓ C.Review the KRI definition and data source to ensure it reflects effective code review.
- D.Adjust the code review coverage threshold to a higher percentage.
Why C: The risk manager must first validate that the KRI for code review coverage is actually measuring the effectiveness of code reviews, not just their completion. If the KRI is green but critical bugs persist, the data source or definition may be flawed—for example, measuring the percentage of code reviewed rather than the quality of reviews. Without this validation, any subsequent action (like adding controls or adjusting thresholds) would be based on unreliable information.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.