CRISC - Risk Response and Reporting - Section 3.1

Evaluate and select risk treatment and response options consistent with the organisation's risk appetite.

Evaluate the four risk treatment options - mitigation, acceptance, transfer, and avoidance - and select the response consistent with the organisation's risk appetite and the cost of each option. Recognise that risk transfer through insurance or contracts shifts financial consequence but does not eliminate the underlying risk.

Risk treatmentRisk acceptanceRisk transferRisk mitigation

Practice question for this objective

Free sampleRisk Response and Reportingmedium

A bank purchases a cyber-insurance policy to fund the financial impact of a customer-data breach. A regulator later asks who remains answerable for protecting that data following the purchase. What should the risk practitioner explain about transferring risk in this way?

  • AThe insurer now bears accountability for safeguarding the customer data once the premium is paid.
  • BTransfer moves the financial impact to the insurer, yet accountability for the risk stays with the bank. Correct
  • CTransferring the risk removes the breach exposure entirely, so the register entry can now be closed.
  • DBuying the policy converts the residual risk into an avoided risk for reporting purposes.
Recognise that risk transfer shifts financial impact to a third party but the organisation retains accountability for the risk. Transfer such as insurance funds the financial consequence of a loss, yet the organisation that owns the activity keeps accountability and any legal or regulatory duty; the residual exposure and its owner therefore remain on the register after the policy is bought.

Why A is wrong: It is tempting to think paying a premium hands over the duty, but an insurer funds loss and never assumes the organisation's legal duty to protect data.

Why B is correct: Insurance shifts the cost of loss to a third party, but the organisation retains accountability and its regulatory duty to protect the data it holds.

Why C is wrong: Closing the entry looks tidy, but transfer addresses only financial impact and the underlying breach exposure and its ownership both remain.

Why D is wrong: Relabelling it as avoided seems convenient, but avoidance means ending the activity, which insuring the data plainly does not achieve.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Risk Response and Reporting objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.