nerdexam
Isaca

CISA · Question #207

When reviewing an organization's finalized risk assessment process, what would be the MAIN reason for an IS auditor to compare acceptable risk level with residual risk?

The correct answer is C. To recommend control enhancements for further risk reduction. Comparing acceptable risk level with residual risk tells an auditor whether the remaining risk (after controls are applied) still exceeds what the organization is willing to tolerate - and if it does, the logical next step is to recommend additional or stronger controls to close

Submitted by rania.sa· Apr 18, 2026Governance and Management of IT

Question

When reviewing an organization’s finalized risk assessment process, what would be the MAIN reason for an IS auditor to compare acceptable risk level with residual risk?

Options

  • ATo advise management on risk appetite levels
  • BTo identify new risks the organization may have to address
  • CTo recommend control enhancements for further risk reduction
  • DTo identify omissions made in the completed risk assessment

How the community answered

(38 responses)
  • A
    11% (4)
  • B
    3% (1)
  • C
    82% (31)
  • D
    5% (2)

Explanation

Comparing acceptable risk level with residual risk tells an auditor whether the remaining risk (after controls are applied) still exceeds what the organization is willing to tolerate - and if it does, the logical next step is to recommend additional or stronger controls to close that gap, making C correct.

Why the distractors are wrong:

  • A is incorrect because acceptable risk levels (risk appetite) are set by management, not advised by the auditor during a risk assessment review - that determination has already been made by this stage.
  • B is incorrect because comparing residual risk to acceptable risk says nothing about new risks; identifying new risks requires a fresh risk identification exercise, not a comparison of existing figures.
  • D is incorrect because omissions in the risk assessment would be caught by reviewing the process or scope itself (e.g., missing assets or threat sources), not by comparing two numerical risk levels.

Memory tip: Think of it as a "gap check" - residual risk is what's left over after controls, and acceptable risk is the finish line. If the leftover exceeds the finish line, you need better controls (C). The auditor isn't setting the finish line (A), finding new races (B), or reviewing the scoreboard for errors (D).

Topics

#Risk Management#Residual Risk#Acceptable Risk#IS Audit Review

Community Discussion

No community discussion yet for this question.

Full CISA Practice