CRISC - Risk Response and Reporting (32% of the exam) - Section 3.3

Establish risk and control ownership to ensure accountability for residual risk and control operation.

Establish risk ownership and control ownership as separate accountabilities, ensuring the risk owner formally accepts residual risk and the control owner is responsible for the control's continued operation. Recognise that ambiguous ownership is itself a governance risk that can leave residual risk unmonitored.

Risk ownershipControl ownershipAccountabilityResidual risk acceptance

Practice question for this objective

Free sampleRisk Response and Reportingmedium

During a control review, a manager is recorded as accountable for ensuring a daily reconciliation control operates as designed, while a separate executive is accountable for the financial misstatement risk the control addresses. How should the risk practitioner describe these two distinct roles?

  • ABoth individuals are control owners, since each one shares accountability for the operation of the daily reconciliation control
  • BBoth individuals are risk owners, since each one is ultimately accountable for the financial misstatement exposure being managed
  • CThe manager is the control owner accountable for the control operating, and the executive is the risk owner accountable for the residual risk Correct
  • DThe executive is the control owner and the manager is the risk owner, reflecting the seniority of each person in the reporting line
Distinguish a control owner, accountable for control operation, from a risk owner, accountable for the residual risk the control addresses. Control ownership and risk ownership are separate accountabilities that often sit with different people. The control owner ensures the control operates as designed, whereas the risk owner remains accountable for the residual risk and decides whether it is acceptable, so a single control may support a risk held by a more senior owner.

Why A is wrong: Sharing the control label is tempting because both are involved, but the executive owns the risk outcome rather than the control mechanism, so the roles are not the same.

Why B is wrong: Calling both risk owners blurs the split, because the manager is accountable for running a control, not for accepting or treating the underlying exposure.

Why C is correct: Control ownership covers a control performing as designed, while risk ownership covers the residual exposure, so the two roles are correctly separated here.

Why D is wrong: Assigning roles by seniority feels intuitive, but ownership follows the responsibility held, so this reverses the two roles and misstates accountability.

See more CRISC practice questions, answers explained.

Exam traps in Risk Response and Reporting

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • The internal audit lead, because the assurance function independently confirms the residual level and can therefore authorise the organisation to live with it

    Why it is wrong: Tempting because audit validates the residual figure, but the assurance function must stay independent and cannot accept a risk it is meant to assure.

  • Record the cloud provider as the control owner, since the party that configures and operates the control day to day is best placed to be accountable for it

    Why it is wrong: Tempting because the provider runs the control, but accountability for the control objective cannot be transferred to a third party by outsourcing operation.

  • The control owner is accountable for setting the organisation risk appetite that determines whether the control is even required

    Why it is wrong: Setting appetite is a governance and board responsibility, so attributing it to the control owner overstates the role and confuses ownership with strategy.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.