Courseiva
hardMultiple ChoiceObjective-mapped

KRI Green but Control Testing Fails? Investigate the KRI Calculation Methodology First

A company monitors key risk indicators (KRIs) using a dashboard. The risk manager notices that a KRI has a green status but the underlying control testing shows a high failure rate. What action should the risk manager take FIRST?

Quick Answer

The answer is to investigate the KRI calculation methodology first. This is correct because a green KRI status paired with a high control failure rate signals a fundamental disconnect in the risk measurement framework; the KRI may be using stale data, incorrect thresholds, or a flawed aggregation formula that masks the true risk exposure. On the CRISC exam, this scenario tests your understanding of the relationship between KRIs and control testing, emphasizing that KRIs are leading indicators that must be validated against actual control performance. A common trap is to immediately adjust the KRI threshold or escalate the issue, but the correct first step is always root cause analysis of the metric itself. Remember the memory tip: “Green KRI, red control? Check the math before you scroll.”

⚠ Common exam trap

Candidates often assume a green KRI means the risk is low and immediately focus on fixing the control (Option D) or adjusting the threshold (Option B), rather than recognizing that the KRI itself may be flawed and requires investigation first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Investigate the KRI calculation methodology

The KRI showing green while the underlying control has a high failure rate indicates a misalignment between the KRI and the actual control effectiveness. The first step is to investigate the KRI calculation methodology to determine if the KRI is measuring the wrong metric, using stale data, or has an incorrect threshold. Only after understanding why the KRI is misleading can the risk manager take appropriate corrective action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Escalate to the risk committee

    Why it's wrong here

    Escalation without analysis does not provide useful information for decision-making.

  • Change the KRI threshold to amber

    Why it's wrong here

    Changing thresholds without investigation could mask the real problem.

  • Investigate the KRI calculation methodology

    Why this is correct

    The KRI might be using incorrect data or outdated baselines.

  • Re-test the control

    Why it's wrong here

    Re-testing assumes the control test is wrong, but the issue may be the KRI.

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CRISC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A technology company has implemented a risk and control monitoring program for its software development lifecycle. The program includes key risk indicators (KRIs) such as number of critical bugs found in production, code review coverage, and time to patch vulnerabilities. After six months, the risk committee noticed that the KRI for code review coverage is consistently green (within threshold), but the number of critical bugs in production remains high. The risk manager suspects a disconnect between the KRI and actual risk. What should the risk manager do FIRST?

easy
  • A.Implement additional testing controls to catch bugs before production.
  • B.Reduce the code review coverage target to lower the risk appetite.
  • C.Review the KRI definition and data source to ensure it reflects effective code review.
  • D.Adjust the code review coverage threshold to a higher percentage.

Why C: The risk manager must first validate that the KRI for code review coverage is actually measuring the effectiveness of code reviews, not just their completion. If the KRI is green but critical bugs persist, the data source or definition may be flawed—for example, measuring the percentage of code reviewed rather than the quality of reviews. Without this validation, any subsequent action (like adding controls or adjusting thresholds) would be based on unreliable information.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.