CRISC - Risk Response and Reporting (32% of the exam) - Section 3.9

Monitor risk and controls through data collection, aggregation and analysis, and manage issues, findings and exceptions.

Monitor risk and controls through continuous data collection, aggregation, and analysis to detect changes in the risk environment or control performance. Manage issues, findings, and exceptions through a structured process that tracks each item to resolution and escalates those that breach defined thresholds.

Risk monitoringControl monitoringIssue managementException management

Practice question for this objective

Free sampleRisk Response and Reportingmedium

A new automated control will replace a manual authorisation step in a high-volume order pipeline at go-live. The risk practitioner wants the implementation itself to avoid halting order processing if the new control behaves unexpectedly on the first day. Which implementation arrangement best manages this go-live risk?

  • ARun the new control in parallel with the retained manual step and keep a tested rollback path until it is confirmed stable Correct
  • BSwitch the entire pipeline to the new automated control overnight so that all orders are covered by it from the first business day
  • CDefer the new control until the manual step has been fully decommissioned and the responsible staff have been reassigned elsewhere
  • DEnable the new control only for the largest customers first because their orders justify the closest monitoring during go-live
Manage control go-live risk by running the new control in parallel with the old one and keeping a tested rollback until stability is confirmed. Implementing a control is itself a source of risk, because a newly deployed control can behave unexpectedly in production. Running the new automated control in parallel with the retained manual step, backed by a tested rollback path, means order processing continues even if the new control fails on its first day. The parallel period is ended only once monitoring confirms the control is stable, which contains implementation disruption without leaving the objective unprotected.

Why A is correct: Running the new control alongside the existing one with a tested rollback lets processing continue if the new control fails, which is the safest way to manage go-live disruption risk.

Why B is wrong: A clean overnight cutover is simplest to coordinate, but it leaves no fallback if the new control misbehaves, so a first-day fault could halt the whole order pipeline.

Why C is wrong: Removing the manual step first feels tidy, but it destroys the very fallback that would protect processing during the risky early period of the new control.

Why D is wrong: Targeting the biggest customers concentrates rather than reduces exposure, since any first-day fault would then strike the most important orders without a fallback in place.

See more CRISC practice questions, answers explained.

Exam traps in Risk Response and Reporting

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • Deploy the access changes directly to all production systems at once so that the least-privilege state is achieved on a single date

    Why it is wrong: A single big-bang change reaches the target state fastest, but it gives no chance to catch errors, so a misconfiguration could lock out legitimate users across the whole estate.

  • Forward each raw source feed to senior management separately so that leaders can read the original detail and reach their own conclusion

    Why it is wrong: Sending raw feeds shifts the analysis burden onto leaders and offers no consistent view, so meaningful comparison and trend reporting across sources is not possible.

  • A key performance indicator that reports how efficiently the payment team processed transactions over the last reporting month

    Why it is wrong: A performance indicator measures operational throughput and efficiency, which is useful for service management but does not signal movement of risk towards an appetite limit.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.