CRISC Certified in Risk and Information Systems Control – Question366

Which negative risk response usually has a contractual agreement?

A.
Sharing
B. Transference
C. Mitigation
D. Exploiting

Correct Answer: B

Explanation:

Explanation:
Transference is the risk response that transfers the risk to a third party, usually for a fee. Insurance and subcontracting of dangerous works are two common examples of transference with a contractual obligation.
Incorrect Answers:
A: Sharing is a positive risk response. Note that sharing may also have contractual obligations, sometimes called teaming agreements.
C: Mitigation is a negative risk response used to lower the probability and/or impact of a risk event.
D: Exploiting is a positive risk response and not a negative response and doesn’t have contractual obligations.