Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CRISC Risk Response, Ownership and Reporting

Updated 10 min read
Key takeaway

Risk response means choosing what to do about a risk.

  • You can reduce it, avoid the activity causing it, share or transfer part of it, or accept it.
  • For example, backups reduce the risk of losing data.
  • The person responsible for the risk approves the response within their authority.
On this page9 sections
  1. Risk response
  2. Risk and control owners
  3. Treatment options
  4. Worked example: a cloud recovery gap
  5. Exceptions and risk acceptance
  6. Residual risk monitoring
  7. Risk reports
  8. Decision sequence
  9. Worked decision

Risk response

A risk response is the action an organization chooses after identifying a possible problem and estimating how serious it could be. If a system outage could interrupt sales, the business might install a backup system to reduce the disruption. It could also stop using the unreliable system, transfer part of the financial loss through insurance, or accept the remaining risk. The choice depends on the likely harm, the cost of the response and any legal requirements. The risk owner is the person accountable for this decision. Specialists help assess the options and carry out the approved response.

The current CRISC outline gives Risk Response and Reporting the largest share, 32 percent. Questions in this area can ask how to choose among treatment options, define accountability, monitor residual risk, or communicate a decision. They reward answers that keep assessment, decision authority, implementation, and monitoring connected.

Risk and control owners

A risk owner is accountable for the business exposure and its treatment decision. Depending on the organization, that person may be a process executive, product leader, or service owner with formal authority. A control owner operates or maintains a safeguard, such as access review or backup monitoring. The control owner can report how well the control works, but does not automatically have authority to accept the business risk.

Risk and control specialists support informed decisions. They establish methods, gather evidence, analyze scenarios, challenge assumptions, and advise on treatment. A governance body sets criteria, tolerances, and escalation routes. Internal audit may independently assess whether governance and controls are working; it should not become the owner of management’s risk decision or design controls it will later audit.

One person can occupy more than one role in a small organization, but the responsibilities still need to be clear. The exam scenario may identify a title without stating that the person has acceptance authority. Read the delegation and governance facts. A senior title alone does not justify bypassing the organization’s approval process.

Treatment options

Common response strategies include avoiding an activity, reducing likelihood or impact, sharing or transferring part of the exposure, and accepting risk within defined authority. Terminology differs among frameworks, and the organization’s policy controls. The candidate should identify what exposure remains, who can decide, and whether the proposed action addresses the scenario.

Avoidance can mean stopping or redesigning an activity so a particular exposure no longer arises. It may also sacrifice a business objective. Reduction applies measures intended to lower likelihood or impact, such as stronger authentication or tested recovery. Sharing may allocate responsibilities or financial consequences through insurance or a contract, but it rarely removes the organization’s accountability for its own obligations. Acceptance is a deliberate decision that residual risk is within tolerance, made by an authorized owner and documented with a review trigger.

A response should be feasible and proportionate. “Install a control” is not a complete plan unless the measure has an owner, funding, target date, evidence of operation, and a way to evaluate residual exposure. Conversely, an expensive safeguard can create operational friction or new risk. Compare reasonable options against business impact, risk criteria, control effectiveness, and the cost or disruption of treatment.

Worked example: a cloud recovery gap

A retailer’s order service runs in a cloud region. The team reports successful nightly backups, but a recovery exercise shows that the restored database is missing recent transactions and the application cannot meet its recovery time objective. Orders are processed throughout the day, and the business owner’s tolerance for lost transactions is low. A technology manager proposes buying another backup product and marking the risk closed.

First define the risk in business terms: a regional or service failure could interrupt order fulfillment and lose transactions because backups and recovery procedures do not meet the agreed objectives. Verify the backup scope, restore-point evidence, dependencies, recovery time, and ownership of the service. The backup product itself is not proof of recoverability.

The service risk owner should compare treatment options with the business objectives. Possible actions include changing replication frequency, redesigning recovery architecture, testing an alternate region, or modifying the service process. The control owner can implement and evidence the technical measures; the risk owner approves funding and accepts or escalates any residual exposure. The analyst should recommend actions and record the basis, not accept on the owner’s behalf.

Define measurable milestones: an approved recovery design, a successful test that restores data within the agreed recovery point and time objectives, and recurring exercises that include application dependencies. Until evidence demonstrates effectiveness, the response is in progress. If the residual risk exceeds tolerance or a deadline cannot be met, escalate the decision to the level authorized to change scope, accept exposure, or pause the affected service.

This example illustrates why an additional product is not automatically the best answer. The gap is failure to meet a business recovery outcome. A control should be selected and tested against that outcome; the resulting evidence informs the owner’s decision.

Exceptions and risk acceptance

An exception request should identify the requirement that cannot be met, the affected assets or process, the reason, current safeguards, residual exposure, compensating measures, responsible owner, approval authority, expiry or review date, and conditions for withdrawal. A ticket marked “accepted” without these elements can conceal indefinite exposure.

The risk owner should compare the exception with approved criteria and consider legal or contractual requirements that cannot simply be waived internally. A temporary exception might be appropriate while a replacement system is implemented, but it needs interim safeguards, monitoring, a deadline, and escalation if the plan slips. The control owner should not grant an exception merely because implementation is difficult.

Risk acceptance does not mean that risk disappears. It records a decision to retain residual exposure under specified conditions. New incidents, control failures, business changes, threat changes, or an approaching review date can invalidate the original rationale. Reassessment is warranted when facts or the operating context change materially.

Residual risk monitoring

A useful monitoring plan links the risk statement to indicators, thresholds, data sources, frequency, owner, and action when a threshold is crossed. A key risk indicator may show a changing exposure, such as the percentage of critical systems outside a recovery objective. A key control indicator may show whether a safeguard operates as designed, such as completion and exception rates for privileged-access reviews. These measures answer different questions.

Metrics need a reliable denominator and stable collection method. A falling incident count may reflect improved resilience, but it may also reflect underreporting. A high control completion rate may hide weak evidence or a poor control design. Validate source coverage, definition, timeliness, and limitations before presenting a trend as proof that risk is lower.

Monitoring should lead to action. Set thresholds that trigger investigation, treatment changes, or escalation. Assign someone to evaluate the signal and preserve evidence of what was reviewed. Avoid dashboards full of measures with no owner or decision attached. A concise measure that changes a real decision is usually more useful than a larger set of unexplained numbers.

Risk reports

A risk report should help its audience understand the exposure and decide what to do. For an operational owner, include scenario, affected service, current controls, evidence, action, accountable people, due dates, and unresolved dependencies. For executives or a risk committee, summarize material exposures against appetite, trends, exceptions, treatment status, and decisions needed. Keep detailed technical evidence available without forcing every reader through it.

Explain uncertainty and limitations. If a metric omits a business unit, uses stale inventory, or has a changed collection method, disclose that fact next to the result. Do not imply that a control is effective merely because it exists or that risk is acceptable because a score is green. State the criteria, assumptions, and escalation threshold that give the status meaning.

Reporting also requires timely escalation. A risk that exceeds delegated tolerance, threatens a critical objective, or cannot be treated by its due date should reach the proper authority promptly. The analyst should present options and consequences clearly. Concealing an issue until a periodic committee meeting defeats the purpose of monitoring.

Decision sequence

  1. Restate the business objective and the risk scenario in one or two sentences.
  2. Check evidence about exposure, likelihood, impact, and existing safeguards.
  3. Identify the risk owner, control owners, decision authority, and applicable criteria.
  4. Compare feasible response options, including the residual exposure and operational effects.
  5. Document the authorized decision, rationale, actions, measures, owners, dates, and review trigger.
  6. Monitor evidence, report exceptions and trends, and escalate when thresholds or assumptions change.

This sequence is a reasoning aid rather than a rule that every scenario begins with a fresh assessment. If the facts already establish an urgent exposure, immediate containment may be necessary while assessment continues. If the question asks who can accept risk, authority is central. If it asks how to select treatment, compare options with criteria and business impact. The requested action and stated facts determine the best next step.

Worked decision

A company’s payment processor has missed two monthly vulnerability remediation targets. A security analyst proposes suspending all payment traffic. The business owner says an outage would disrupt revenue, while the vendor says the issue affects only an internal management interface. The organization has not validated the vendor’s network diagram or tested whether the interface is reachable from its environment. What should the risk professional recommend first?

  1. Accept the vendor’s statement because the issue is internal to its environment.
  2. Have the risk owner immediately accept the exposure to avoid a service interruption.
  3. Validate the affected interface, connectivity, compensating controls, and business impact, then present treatment options and escalation needs to the authorized owner.
  4. Suspend the entire payment service before confirming exposure or available safeguards.

Best answer: C. The facts are incomplete and materially affect likelihood and impact. Validate reachability, affected assets, vendor evidence, existing controls, and service dependencies. Then frame proportionate options for the authorized owner, which could include targeted restrictions, compensating controls, a remediation deadline, or escalation. If validation reveals imminent exploitation or unacceptable exposure, urgent containment may be justified.

A is weak because an interested vendor statement is not sufficient evidence. B skips assessment and misuses acceptance as a shortcut. D may be disproportionate before understanding the interface and available targeted measures, although containment could become appropriate if evidence shows an immediate threat. The answer preserves independent validation, clear authority, and a response tied to actual exposure.

Common questions

Who accepts information systems risk?

The risk owner or a person with documented delegated authority accepts risk. Analysts and control owners support the decision and implement assigned actions.

Does a supplier contract transfer all risk?

No. Contracts can allocate responsibilities and remedies, but the organization retains obligations tied to its business, data, customers, and applicable requirements.

How should a risk exception be documented?

Record scope, rationale, current safeguards, residual exposure, approval, compensating measures, owner, expiry or review date, and conditions for escalation or withdrawal.

What is the difference between a risk indicator and a control indicator?

A risk indicator signals exposure trends; a control indicator measures safeguard operation. Each needs a clear definition, source, owner, threshold, and response.