Isaca Certified in Risk and Information Systems Control CRISC Question # 487 Topic 49 Discussion
CRISC Exam Topic 49 Question 487 Discussion:
Question #: 487
Topic #: 49
An organization’s expense claim system allows users to split large transactions into smaller ones to bypass limits. What should the risk practitioner do?
A.
Conduct an audit to determine the frequency of occurrence
This behavior representsintentional circumvention of control, requiring formal documentation and assessment as anoncompliance risk scenario.
CRISC principle:
“When control circumvention occurs, the risk practitioner should document the event as a noncompliance risk scenario to evaluate its impact and treatment.”
The other options—auditing, probability updates, or cost analysis—may follow, but the first step isformal recognitionof the risk within the risk register via a new scenario.
CRISC Reference:Domain 2 – IT Risk Assessment, Topic: Scenario Development and Control Evaluation.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit