nerdexam
Isaca

CISM · Question #528

An organization is MOST likely to accept the risk of noncompliance with a new regulatory requirement when:

The correct answer is D. the cost of complying with the regulation exceeds the potential penalties.. When the cost of implementing the required controls outweighs the expected penalties for noncompliance, organizations will often choose to accept the risk rather than incur disproportionate expense.

Submitted by olafpl· Apr 18, 2026Information Security Risk Management

Question

An organization is MOST likely to accept the risk of noncompliance with a new regulatory requirement when:

Options

  • Aemployees are resistant to the controls required by the new regulation.
  • Bthe regulatory requirement conflicts with business requirements.
  • Cthe risk of noncompliance exceeds the organization's risk appetite.
  • Dthe cost of complying with the regulation exceeds the potential penalties.

How the community answered

(68 responses)
  • A
    12% (8)
  • B
    4% (3)
  • C
    3% (2)
  • D
    81% (55)

Explanation

When the cost of implementing the required controls outweighs the expected penalties for noncompliance, organizations will often choose to accept the risk rather than incur disproportionate expense.

Topics

#Risk acceptance#Compliance risk#Cost-benefit analysis#Regulatory compliance

Community Discussion

No community discussion yet for this question.

Full CISM Practice