A bank outsources statement printing to a vendor that, the bank later learns, subcontracts the actual mail handling to an offshore firm holding customer addresses. The risk register records only the printing vendor. To manage this exposure across the vendor lifecycle, what should the risk practitioner do first?
- ATerminate the printing contract immediately, because any undisclosed subcontractor handling customer data is an unacceptable breach of the agreement.
- BIdentify and assess the fourth-party subcontractor's controls over the customer data and update the risk register to reflect that dependency. Correct
- CAsk the printing vendor to confirm in writing that the subcontractor follows the same controls the printing vendor itself applies.
- DRaise the printing vendor's inherent risk rating and schedule the next annual reassessment to capture the new subcontracting arrangement.
Why A is wrong: Tempting because subcontracting customer data feels severe, but reacting before understanding the exposure skips the assessment needed and may breach notice terms in the contract.
Why B is correct: Correct because the offshore firm is a fourth party whose data handling drives the real exposure, so it must be identified, assessed and recorded before any response is chosen.
Why C is wrong: Tempting since a written attestation seems quick, but an unverified assurance from the vendor about its own subcontractor gives no independent evidence the controls actually exist.
Why D is wrong: Tempting because rerating the vendor looks responsive, but deferring to the annual cycle leaves an unassessed fourth-party data exposure live for up to a year.