CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentMedium

A newly implemented enterprise resource planning (ERP) system has undergone a comprehensive risk assessment. Several high-risk items were identified, and management decided to implement new security controls to mitigate these risks. After the controls are in place, the residual risk is still deemed 'High' due to the system's criticality and the remaining inherent vulnerabilities. What is the MOST appropriate next step for the CRISC professional?

  1. ARe-evaluate the effectiveness of the implemented controls.
  2. BInitiate a new cycle of risk identification for the ERP system.
  3. CDocument the 'High' residual risk and proceed with system operation.
  4. DPresent the 'High' residual risk to senior management for formal acceptance.
Show answer & explanation

Correct answer: D. Present the 'High' residual risk to senior management for formal acceptance.

When residual risk remains high after mitigation efforts, it moves beyond the operational team's authority. Senior management must be informed and formally accept the remaining high risk, understanding the potential consequences and making an informed business decision to proceed or mandate further action.

Why the other options are wrong

  • A. While re-evaluation is good practice, it's not the *most appropriate next step* when the risk is already deemed 'High' and requires a management decision.
  • B. A new cycle of risk identification is premature; the focus should be on the *identified* high residual risk.
  • C. Operating with unaccepted high residual risk is irresponsible; formal acceptance is required.

Residual Risk Acceptance

The formal acknowledgement and agreement by management to tolerate the remaining risk after all mitigation and control activities have been implemented.

  • Occurs when risk cannot be fully eliminated or treated economically.
  • Requires informed decision-making by appropriate authority.
  • Should be formally documented.

Memory trick: After treating, what's left must be 'Accepted' or 'Addressed More'.

More IT Risk Assessment questions