CRISC - Risk Response and Reporting (32% of the exam) - Section 3.4

Manage third-party and supply chain risk across the vendor lifecycle, including fourth-party dependencies.

Manage third-party and supply chain risk across the full vendor lifecycle - from due diligence and contracting through ongoing monitoring to offboarding. Extend this analysis to fourth-party risk by identifying critical sub-processors whose failure could cascade into the organisation despite no direct contractual relationship.

Third-party riskSupply chain riskFourth-party riskVendor management

Practice question for this objective

Free sampleRisk Response and Reportinghard

A bank outsources statement printing to a vendor that, the bank later learns, subcontracts the actual mail handling to an offshore firm holding customer addresses. The risk register records only the printing vendor. To manage this exposure across the vendor lifecycle, what should the risk practitioner do first?

  • ATerminate the printing contract immediately, because any undisclosed subcontractor handling customer data is an unacceptable breach of the agreement.
  • BIdentify and assess the fourth-party subcontractor's controls over the customer data and update the risk register to reflect that dependency. Correct
  • CAsk the printing vendor to confirm in writing that the subcontractor follows the same controls the printing vendor itself applies.
  • DRaise the printing vendor's inherent risk rating and schedule the next annual reassessment to capture the new subcontracting arrangement.
Fourth-party dependencies that touch sensitive data must be identified, assessed and recorded before a risk response is selected. The exposure sits with the offshore subcontractor that actually holds customer addresses, so the practitioner cannot choose a sound response until that fourth party is mapped, its controls assessed and the dependency reflected in the register.

Why A is wrong: Tempting because subcontracting customer data feels severe, but reacting before understanding the exposure skips the assessment needed and may breach notice terms in the contract.

Why B is correct: Correct because the offshore firm is a fourth party whose data handling drives the real exposure, so it must be identified, assessed and recorded before any response is chosen.

Why C is wrong: Tempting since a written attestation seems quick, but an unverified assurance from the vendor about its own subcontractor gives no independent evidence the controls actually exist.

Why D is wrong: Tempting because rerating the vendor looks responsive, but deferring to the annual cycle leaves an unassessed fourth-party data exposure live for up to a year.

See more CRISC practice questions, answers explained.

Exam traps in Risk Response and Reporting

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • Extend the onboarding questionnaire so it captures far more detail, on the basis that a deeper initial review will stay accurate for the full contract term.

    Why it is wrong: Tempting because richer due diligence feels thorough, but any point-in-time review ages as the vendor changes, so depth at onboarding does not keep the picture current.

  • A clause capping the provider's total liability for any single incident, so the insurer's financial exposure to a subcontractor failure is fixed and predictable from the outset.

    Why it is wrong: Tempting because a liability cap looks like risk control, but limiting payout neither reveals nor governs the subcontractors, so the underlying fourth-party exposure is untouched.

  • Accept the risk formally and record it in the register, since the supplier remains responsible for maintaining the library it ships.

    Why it is wrong: Tempting because acceptance is a valid response, but it leaves the concentration untreated and relies on a maintainer the supplier does not actually control.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.