Which SDLC Risk Should Concern a Practitioner Most?
Which of the following should be of MOST concern to a risk practitioner reviewing the system development life cycle (SDLC)?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests prioritization of control failures in SDLC phases, with the common trap being mistaking process deviations for higher risks than fundamental control overrides like SoD.
This CRISC question tests your ability to identify critical control weaknesses within the System Development Life Cycle (SDLC). The community overwhelmingly agrees that overriding segregation of duties (SoD) poses the highest risk due to potential fraud, errors, and compromised system integrity.
Option B is frequently chosen incorrectly because practitioners often assume exclusive IT involvement invalidates testing; however, while suboptimal, it does not carry the same immediate fraud and compliance risk as overriding segregation of duties.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Segregation of duties (SoD) is a foundational internal control designed to prevent fraud, errors, and unauthorized activities by ensuring no single individual controls an entire process. Overriding SoD during any SDLC phase, especially user testing, removes critical checks and balances, directly exposing the organization to financial loss, data breaches, and compliance violations. For a CRISC risk practitioner, preserving control integrity always outweighs procedural inefficiencies, making this the most severe concern.Why the Other Options Are Wrong
Option B describes incomplete testing validation, which is a quality issue but lacks the direct fraud and control breakdown associated with SoD overrides. Option C is actually a best practice, as data anonymization protects sensitive information throughout testing cycles. Option D reflects standard SDLC methodology where user acceptance testing logically concludes the development cycle before production deployment. None of these alternatives present an immediate, high-impact control failure comparable to bypassing SoD.Community Comment Notes
Multiple highly-rated comments emphasize that SoD overrides fundamentally undermine auditability and system reliability, introducing unchecked opportunities for malicious activity or accidental errors. Contributors note that while IT-led testing or phased approaches may require remediation, they do not compromise the core governance framework like SoD bypasses do. The consensus reinforces that risk practitioners must prioritize control environment weaknesses over operational workflow preferences.Official Reference
Exam Strategy
When evaluating SDLC scenarios on the CRISC exam, always prioritize fundamental control weaknesses over process inefficiencies or workflow preferences. Use the risk-based approach by asking which option creates the highest likelihood of fraud, data breach, or compliance failure, as ISACA consistently rewards answers that protect the control environment first.
Related Analysis
Practice All CRISC Questions
Access 332 questions with complete answers and detailed explanations.
View Full CRISC Practice Test →