This behavior represents intentional circumvention of control, requiring formal documentation and assessment as a noncompliance risk scenario. CRISC principle: "When control circumvention occurs, the risk practitioner should document the event as a noncompliance risk scenario to evaluate its impact and treatment." The other options-auditing, probability updates, or cost analysis-may follow, but the first step is formal recognition of the risk within the risk register via a new scenario. CRISC Reference: Domain 2 - IT Risk Assessment, Topic: Scenario Development and Control Evaluation.