Certified in Risk and Information Systems Control (CRISC) — Question 192

An organization has outsourced its lease payment process to a service provider who lacks evidence of compliance with a necessary regulatory standard. Which risk treatment was adopted by the organization?

Answer options

Correct answer: A

Explanation

The organization has accepted the risk by outsourcing the lease payment process without ensuring compliance, indicating a choice to live with the potential consequences. The other options, such as Transfer or Mitigation, would involve taking steps to reduce or shift the risk, while Avoidance would mean not engaging in the risky activity at all.