Which SDLC Risk Should Concern a Practitioner Most?

Which of the following should be of MOST concern to a risk practitioner reviewing the system development life cycle (SDLC)?

  1. Segregation of duties controls are overridden during user testing phases Source Reference Answer
  2. Testing is completed by IT support users without input from end users
  3. Data anonymization is used during all cycles of end user testing
  4. Testing is completed in phases with user testing scheduled as the final phase

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests prioritization of control failures in SDLC phases, with the common trap being mistaking process deviations for higher risks than fundamental control overrides like SoD.

This CRISC question tests your ability to identify critical control weaknesses within the System Development Life Cycle (SDLC). The community overwhelmingly agrees that overriding segregation of duties (SoD) poses the highest risk due to potential fraud, errors, and compromised system integrity.

Option B is frequently chosen incorrectly because practitioners often assume exclusive IT involvement invalidates testing; however, while suboptimal, it does not carry the same immediate fraud and compliance risk as overriding segregation of duties.

Community Discussion (3 comments)

d9iceguy 👍 1 Selected: A
Overriding segregation of duties (SoD) controls poses the greatest risk in the SDLC because it: Introduces the potential for unauthorized changes, fraud, errors, or malicious activities. Undermines fundamental controls meant to ensure the integrity and reliability of the system. Can significantly compromise security, auditability, and compliance throughout the development lifecycle. Why not the other options? B. Testing by IT support users without end-user input: A concern for functionality or usability, but less severe than overriding critical security controls. C. Data anonymization used during end-user testing: Actually reduces risk by protecting sensitive data. D. User testing as the final phase: A standard approach in many SDLC methodologies; not inherently a significant risk.
lferolm 👍 1 Selected: A
Segregation of duties controls are overridden during user testing phases: This is the most concerning issue for a risk practitioner because segregation of duties (SoD) is a critical internal control designed to prevent conflicts of interest and reduce the risk of errors and fraud. Overriding these controls during any phase of the SDLC, including user testing, can lead to significant risks such as unauthorized access, manipulation of data, and lack of accountability. This concern directly impacts the integrity, security, and reliability of the system being developed.
Baddest 👍 2
A. Segregation of duties controls are overridden during user testing phases Segregation of duties controls are critical for preventing fraud and errors by ensuring that no single individual has the ability to execute a critical process from beginning to end without oversight. Overriding these controls during user testing phases could potentially lead to unauthorized or inappropriate actions being taken, increasing the risk of fraud, errors, or data breaches. Therefore, a risk practitioner would be particularly concerned if segregation of duties controls were compromised during any phase of the SDLC, as it could introduce significant risks to the development process and the resulting system

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Segregation of duties (SoD) is a foundational internal control designed to prevent fraud, errors, and unauthorized activities by ensuring no single individual controls an entire process. Overriding SoD during any SDLC phase, especially user testing, removes critical checks and balances, directly exposing the organization to financial loss, data breaches, and compliance violations. For a CRISC risk practitioner, preserving control integrity always outweighs procedural inefficiencies, making this the most severe concern.

Why the Other Options Are Wrong

Option B describes incomplete testing validation, which is a quality issue but lacks the direct fraud and control breakdown associated with SoD overrides. Option C is actually a best practice, as data anonymization protects sensitive information throughout testing cycles. Option D reflects standard SDLC methodology where user acceptance testing logically concludes the development cycle before production deployment. None of these alternatives present an immediate, high-impact control failure comparable to bypassing SoD.

Community Comment Notes

Multiple highly-rated comments emphasize that SoD overrides fundamentally undermine auditability and system reliability, introducing unchecked opportunities for malicious activity or accidental errors. Contributors note that while IT-led testing or phased approaches may require remediation, they do not compromise the core governance framework like SoD bypasses do. The consensus reinforces that risk practitioners must prioritize control environment weaknesses over operational workflow preferences.

Official Reference

Exam Strategy

When evaluating SDLC scenarios on the CRISC exam, always prioritize fundamental control weaknesses over process inefficiencies or workflow preferences. Use the risk-based approach by asking which option creates the highest likelihood of fraud, data breach, or compliance failure, as ISACA consistently rewards answers that protect the control environment first.

Related Analysis

Practice All CRISC Questions

Access 332 questions with complete answers and detailed explanations.

View Full CRISC Practice Test →

← Back to CRISC Study Guide