CRISC - Risk Response and Reporting (32% of the exam) - Section 3.1

Evaluate and select risk treatment and response options consistent with the organisation's risk appetite.

Evaluate the four risk treatment options - mitigation, acceptance, transfer, and avoidance - and select the response consistent with the organisation's risk appetite and the cost of each option. Recognise that risk transfer through insurance or contracts shifts financial consequence but does not eliminate the underlying risk.

Risk treatmentRisk acceptanceRisk transferRisk mitigation

Practice question for this objective

Free sampleRisk Response and Reportingmedium

A bank purchases a cyber-insurance policy to fund the financial impact of a customer-data breach. A regulator later asks who remains answerable for protecting that data following the purchase. What should the risk practitioner explain about transferring risk in this way?

  • AThe insurer now bears accountability for safeguarding the customer data once the premium is paid.
  • BTransfer moves the financial impact to the insurer, yet accountability for the risk stays with the bank. Correct
  • CTransferring the risk removes the breach exposure entirely, so the register entry can now be closed.
  • DBuying the policy converts the residual risk into an avoided risk for reporting purposes.
Recognise that risk transfer shifts financial impact to a third party but the organisation retains accountability for the risk. Transfer such as insurance funds the financial consequence of a loss, yet the organisation that owns the activity keeps accountability and any legal or regulatory duty; the residual exposure and its owner therefore remain on the register after the policy is bought.

Why A is wrong: It is tempting to think paying a premium hands over the duty, but an insurer funds loss and never assumes the organisation's legal duty to protect data.

Why B is correct: Insurance shifts the cost of loss to a third party, but the organisation retains accountability and its regulatory duty to protect the data it holds.

Why C is wrong: Closing the entry looks tidy, but transfer addresses only financial impact and the underlying breach exposure and its ownership both remain.

Why D is wrong: Relabelling it as avoided seems convenient, but avoidance means ending the activity, which insuring the data plainly does not achieve.

See more CRISC practice questions, answers explained.

Exam traps in Risk Response and Reporting

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • Accept the residual exposure because the probability of a breach is judged to be low.

    Why it is wrong: Low probability tempts acceptance, but an impact beyond the firm's capacity to absorb makes pure acceptance reckless for a potentially ruinous loss.

  • Accept the residual risk and proceed, monitoring the regulatory situation as it develops.

    Why it is wrong: Acceptance and monitoring is tempting for opportunity, but knowingly retaining a risk that stays above appetite breaches the organisation's own limits.

  • Avoid the risk by suspending the statutory reporting until the residual falls within appetite.

    Why it is wrong: Avoidance removes exposure by stopping the activity, but a legally mandated obligation cannot be suspended, so avoidance is not a lawful option here.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.