Which statement BEST distinguishes IT vendor management from third-party risk management as the IS auditor would evaluate them?
- AVendor management is concerned with cyber risk only, whereas third-party risk management covers the wider commercial relationship with each strategic supplier of the organisation.
- BVendor management is a board-level oversight activity, while third-party risk management is delegated to procurement to negotiate price reductions and renewal terms with suppliers.
- CVendor management focuses on commercial performance against service-level targets, while third-party risk management focuses on the residual risk the relationship introduces across the enterprise. Correct
- DVendor management addresses only outsourced data centres, while third-party risk management addresses software-as-a-service and other cloud arrangements that bypass classical procurement.
Why A is wrong: This inverts the disciplines, since vendor management is the broader commercial discipline and third-party risk management is the risk-focused overlay; an auditor would mark this confusion as incorrect.
Why B is wrong: This is tempting because procurement does sit close to vendors, but governance of third-party risk sits with senior management and the board, not the procurement desk; this misallocates accountability.
Why C is correct: This captures the recognised split: vendor management is performance and contract-led, while third-party risk management is risk-led and covers information security, resilience, compliance and concentration exposure across the supplier portfolio.
Why D is wrong: This narrow framing is plausible to a candidate thinking only of hosting, but both disciplines apply across the whole supplier portfolio regardless of delivery model, so the scope claim is wrong.