Which Scenario Represents Risk Sharing in CRISC?

Which of the following is an example of risk sharing?

  1. Rejecting a high-risk project
  2. Outsourcing the hosting of a critical system
  3. Investing in fault-tolerant technology
  4. Engaging in a code escrow agreement Source Reference Answer

Community Votes

D
50%
B
50%

50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests precise classification of risk responses, with the common trap being the overlap between risk transfer and risk sharing when evaluating third-party contracts.

This CRISC practice question evaluates your understanding of risk treatment categories, focusing on distinguishing risk sharing from avoidance, mitigation, and transfer. Community consensus identifies outsourcing as the correct choice due to its inherent distribution of operational risk between organizations.

Candidates often select D (code escrow) or C (fault-tolerant technology), misclassifying risk mitigation or asset protection mechanisms as risk sharing rather than recognizing their standalone protective nature.

Community Discussion (3 comments)

Sara98 👍 2 Selected: B
Option D is a type of risk transfer, but it doesn't necessarily involve sharing the risk with another party. A code escrow agreement is typically used to protect a software development project by ensuring that the source code is held in trust by a third party.
Sara98 👍 1 Selected: B
Sure it’s B
Baddest 👍 3 Selected: D
D. Engaging in a code escrow agreement In a code escrow agreement, the source code of a software application is deposited with a third-party escrow agent. If the software vendor fails to meet certain obligations, such as maintaining the software or providing support, the source code can be released to the licensee. By engaging in a code escrow agreement, the risk associated with reliance on the software vendor is shared between the vendor and the licensee. If the vendor fails to fulfill its obligations, the licensee has access to the source code, mitigating the risk of dependency on the vendor.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B correctly demonstrates risk sharing because outsourcing hosting responsibilities delegates technical execution and maintenance burdens to a vendor, creating a shared accountability model. Modern CRISC frameworks recognize that contractual service arrangements distribute operational risk across both parties, unlike pure transfer scenarios where liability is completely shifted. This collaborative approach aligns with how organizations manage complex IT dependencies through structured vendor partnerships.

Why the Other Options Are Wrong

Option A represents risk avoidance, as declining the project eliminates exposure entirely. Option C is a risk mitigation control designed to reduce system downtime and impact without external risk distribution. Option D functions as risk transfer or mitigation, securing source code access upon vendor default rather than establishing ongoing shared risk exposure.

Community Comment Notes

As highlighted in top-rated feedback, users emphasize that outsourcing requires continuous vendor collaboration and joint SLA management, distinguishing it from simple liability shifts. Several commenters point out that escrow agreements merely hold assets in trust, failing to meet the active risk-distribution criteria. The prevailing view supports B after systematically ruling out avoidance and technical mitigation options.

Official Reference

Exam Strategy

Always eliminate absolute controls like fault tolerance and outright rejection first, then compare third-party options against ISACA’s definitions of transfer versus shared accountability. Practice mapping real-world scenarios to risk treatment matrices to avoid getting trapped by semantically similar contract types.

Related Analysis

Practice All CRISC Questions

Access 332 questions with complete answers and detailed explanations.

View Full CRISC Practice Test →

← Back to CRISC Study Guide