CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingHard

A retail company has implemented a new point-of-sale (POS) system across all its stores. To ensure the system processes transactions accurately and securely, the company has implemented several controls: encryption for card data, daily reconciliation of transactions, and quarterly vulnerability scans. After six months, an internal audit reveals that while encryption is working, the daily reconciliation process is often delayed, and vulnerability scan reports are not consistently reviewed. Which of the following statements BEST describes the overall control effectiveness for the POS system?

  1. AThe controls are partially effective, with some operating as intended and others failing.
  2. BThe controls are ineffective due to the lack of consistent review of scan reports.
  3. CThe controls are fully effective, as encryption is functioning correctly.
  4. DThe controls are over-engineered, leading to operational inefficiencies.
Show answer & explanation

Correct answer: A. The controls are partially effective, with some operating as intended and others failing.

The scenario describes a mixed bag: one control (encryption) is working, but two others (reconciliation and vulnerability scan review) are not operating effectively. This indicates partial effectiveness, where some controls contribute to risk reduction while others fail, leading to residual risk.

Why the other options are wrong

  • B. The controls are not entirely ineffective, as at least one (encryption) is working. This option is too absolute.
  • C. While encryption is effective, the ineffectiveness of other critical controls means the overall control environment is not 'fully effective'.
  • D. The scenario describes control failures, not over-engineering. Inefficiencies might exist due to failures, but 'over-engineered' isn't the primary description of the problem.

Control Effectiveness Assessment

The process of evaluating whether controls are suitably designed and operating as intended to achieve their objectives and mitigate risks to acceptable levels.

  • Assesses both design effectiveness and operational effectiveness.
  • Controls can be fully effective, partially effective, or ineffective.
  • Critical for determining residual risk.
  • Requires regular monitoring and testing.

Memory trick: Effectiveness is a Spectrum, Not a Simple Switch.

More Risk Response and Reporting questions