CRISC - Risk Response and Reporting - Section 3.8

Test controls and evaluate their effectiveness in reducing risk to an acceptable level.

Test controls and evaluate their effectiveness by assessing both design effectiveness - whether the control is capable of meeting its objective - and operating effectiveness - whether it is actually working as designed over time. Use assurance results to determine whether residual risk remains within acceptable thresholds.

Control testingControl effectivenessDesign vs operating effectivenessAssurance

Practice question for this objective

Free sampleRisk Response and Reportingmedium

After a control test, a reviewer confirms that an automated reconciliation ran on schedule and matched every transaction for the period. The residual risk, however, still sits above the level the risk owner has accepted. What should the practitioner conclude when judging control effectiveness?

  • AThe control is fully effective because the automated reconciliation ran on schedule and produced no exceptions during the entire period under examination.
  • BThe control is fully effective, and the remaining gap should be reported as an unavoidable inherent risk that no further control activity could realistically reduce.
  • CThe control is ineffective and must be replaced entirely, because any residual risk above appetite proves the existing reconciliation logic was the wrong control to choose.
  • DThe control is operating as designed yet not effective overall, because residual risk remains above the accepted level and additional treatment is still required. Correct
Control effectiveness is judged against reducing residual risk to the accepted level, not merely by whether the control ran without exceptions. A control can operate exactly as designed and still leave residual risk above appetite, so the test of effectiveness is the resulting risk level rather than clean execution, which is why further treatment is needed when the gap persists.

Why A is wrong: Tempting because clean operation looks like success, but effectiveness is measured against reducing risk to the accepted level, which has not been achieved here.

Why B is wrong: Tempting since some risk is inherent, but labelling the gap unavoidable ignores that residual risk above appetite still signals the control is not yet sufficient.

Why C is wrong: Tempting as a strong response, but a working control that leaves a gap may need supplementing rather than wholesale replacement, so this overstates the failure.

Why D is correct: Correct because effectiveness is judged by whether risk is reduced to the accepted level, so a control that runs cleanly but leaves excess residual risk is not yet effective.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Risk Response and Reporting objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.