Isaca
CISM · Question #528
An organization is MOST likely to accept the risk of noncompliance with a new regulatory requirement when:
The correct answer is D. the cost of complying with the regulation exceeds the potential penalties.. When the cost of implementing the required controls outweighs the expected penalties for noncompliance, organizations will often choose to accept the risk rather than incur disproportionate expense.
Submitted by olafpl· Apr 18, 2026Information Security Risk Management
Question
An organization is MOST likely to accept the risk of noncompliance with a new regulatory requirement when:
Options
- Aemployees are resistant to the controls required by the new regulation.
- Bthe regulatory requirement conflicts with business requirements.
- Cthe risk of noncompliance exceeds the organization's risk appetite.
- Dthe cost of complying with the regulation exceeds the potential penalties.
How the community answered
(68 responses)- A12% (8)
- B4% (3)
- C3% (2)
- D81% (55)
Explanation
When the cost of implementing the required controls outweighs the expected penalties for noncompliance, organizations will often choose to accept the risk rather than incur disproportionate expense.
Topics
#Risk acceptance#Compliance risk#Cost-benefit analysis#Regulatory compliance
Community Discussion
No community discussion yet for this question.