CRISC - Risk Response and Reporting - Section 3.4

Manage third-party and supply chain risk across the vendor lifecycle, including fourth-party dependencies.

Manage third-party and supply chain risk across the full vendor lifecycle - from due diligence and contracting through ongoing monitoring to offboarding. Extend this analysis to fourth-party risk by identifying critical sub-processors whose failure could cascade into the organisation despite no direct contractual relationship.

Third-party riskSupply chain riskFourth-party riskVendor management

Practice question for this objective

Free sampleRisk Response and Reportinghard

A bank outsources statement printing to a vendor that, the bank later learns, subcontracts the actual mail handling to an offshore firm holding customer addresses. The risk register records only the printing vendor. To manage this exposure across the vendor lifecycle, what should the risk practitioner do first?

  • ATerminate the printing contract immediately, because any undisclosed subcontractor handling customer data is an unacceptable breach of the agreement.
  • BIdentify and assess the fourth-party subcontractor's controls over the customer data and update the risk register to reflect that dependency. Correct
  • CAsk the printing vendor to confirm in writing that the subcontractor follows the same controls the printing vendor itself applies.
  • DRaise the printing vendor's inherent risk rating and schedule the next annual reassessment to capture the new subcontracting arrangement.
Fourth-party dependencies that touch sensitive data must be identified, assessed and recorded before a risk response is selected. The exposure sits with the offshore subcontractor that actually holds customer addresses, so the practitioner cannot choose a sound response until that fourth party is mapped, its controls assessed and the dependency reflected in the register.

Why A is wrong: Tempting because subcontracting customer data feels severe, but reacting before understanding the exposure skips the assessment needed and may breach notice terms in the contract.

Why B is correct: Correct because the offshore firm is a fourth party whose data handling drives the real exposure, so it must be identified, assessed and recorded before any response is chosen.

Why C is wrong: Tempting since a written attestation seems quick, but an unverified assurance from the vendor about its own subcontractor gives no independent evidence the controls actually exist.

Why D is wrong: Tempting because rerating the vendor looks responsive, but deferring to the annual cycle leaves an unassessed fourth-party data exposure live for up to a year.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Risk Response and Reporting objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.