CRISC · Question #458
After conducting a risk assessment for regulatory compliance, an organization has identified only one possible mitigating control. The cost of the control has been determined to be higher than the…
The correct answer is A. Accept the risk with management sign-off. When the cost of the only identified mitigating control is higher than the penalty of noncompliance, the best recommendation, with management approval, is to accept the risk.
Question
After conducting a risk assessment for regulatory compliance, an organization has identified only one possible mitigating control. The cost of the control has been determined to be higher than the penalty of noncompliance. Which of the following would be the risk practitioner's BEST recommendation?
Options
- AAccept the risk with management sign-off.
- BIgnore the risk until the regulatory body conducts a compliance check.
- CMitigate the risk with the identified control.
- DTransfer the risk by buying insurance.
How the community answered
(35 responses)- A80% (28)
- B6% (2)
- C11% (4)
- D3% (1)
Why each option
When the cost of the only identified mitigating control is higher than the penalty of noncompliance, the best recommendation, with management approval, is to accept the risk.
Risk acceptance is a valid risk treatment strategy when the cost of mitigation outweighs the potential loss from the risk event, or when no other viable treatment options exist. It requires formal acknowledgment and sign-off from management to ensure informed decision-making based on a cost-benefit analysis.
Ignoring the risk is not a recognized risk management strategy and can lead to unmanaged consequences and potential legal liabilities, especially for regulatory compliance.
Mitigating the risk with a control that costs more than the potential penalty is financially inefficient and not the 'BEST' recommendation in this scenario.
Transferring the risk by buying insurance is a valid strategy, but the question specifies 'one possible mitigating control' and accepting the risk explicitly considers the identified cost-benefit. Insurance may not cover all aspects of regulatory non-compliance, such as reputational damage, or might be prohibitively expensive.
Concept tested: Risk acceptance strategy
Topics
Community Discussion
No community discussion yet for this question.