712-50 Question 449
Single answerDesign and manage the third-party assessment process including ongoing compliance managementA global financial services company is expanding its use of third-party SaaS providers for customer onboarding, analytics, and document storage. The board has asked the CISO to redesign the third-party assessment process after an internal audit found that vendors were assessed only at onboarding and not monitored afterward, despite several vendors handling regulated personal and payment data. The procurement team wants a process that is scalable, risk-based, and defensible to regulators. Which approach should the CISO implement FIRST to improve both initial due diligence and ongoing compliance management?
- A
Require every third party to complete the same comprehensive security questionnaire annually, regardless of the type of data they access, to ensure consistent treatment across the vendor population.
- B
Establish a tiered third-party risk management program that classifies vendors by inherent risk and criticality, defines baseline and enhanced due diligence requirements, and assigns review frequency and ongoing monitoring activities based on risk.
- C
Rely primarily on contractual clauses that require vendors to maintain compliance with applicable regulations, and trigger reassessments only when a vendor reports a security incident or compliance breach.
- D
Outsource all third-party assessments to the internal audit function so that business units and security teams can focus on remediation only after deficiencies are formally reported.
Show answer and explanation
Correct answer: B
Explanation
The best first step is to design a formal, risk-based third-party assessment framework rather than applying uniform reviews or relying only on contracts. In practice, the CISO should define vendor tiers using factors such as data classification, network connectivity, business criticality, subcontractor reliance, geographic/regulatory exposure, and concentration risk. Each tier should map to required due diligence artifacts and controls, such as security questionnaires, SOC 2 or ISO/IEC 27001 evidence, privacy reviews, business continuity evidence, penetration test summaries where appropriate, contractual security requirements, and remediation timelines. Ongoing compliance management should include periodic reassessments based on risk, event-triggered reviews for material changes, issue tracking, exception management, and where feasible, external threat or posture monitoring.
This reflects widely accepted practices in third-party risk management and aligns with guidance from sources such as NIST SP 800-161 for supply chain risk management, NIST SP 800-53 control families related to external providers and continuous monitoring, ISO/IEC 27001 and ISO/IEC 27036 for supplier relationships, and financial sector regulatory expectations that emphasize risk-based oversight rather than one-time onboarding checks. For a CCISO-level leader, the key is building governance and operating processes that are scalable, measurable, and defensible to regulators and auditors.
- A. Incorrect.
This is incorrect because applying the same depth of assessment to all third parties is not risk-based and does not scale well. A low-risk vendor with no access to sensitive data should not consume the same assessment effort as a high-risk processor of regulated information. Annual questionnaires alone also do not constitute effective ongoing monitoring; they are a point-in-time activity and may miss material changes between review cycles.
- B. Correct.
This is correct because a tiered, risk-based third-party risk management approach aligns assessment rigor and review cadence to vendor inherent risk, data sensitivity, business criticality, and service impact. It supports scalable onboarding due diligence and ongoing compliance management through differentiated controls such as contract requirements, evidence review, control attestations, issue tracking, periodic reassessment, external monitoring, and trigger-based reviews when changes occur. This approach is consistent with common practices in mature vendor risk programs and regulatory expectations.
- C. Incorrect.
This is incorrect because contracts are necessary but not sufficient. Contractual language establishes obligations, but it does not verify that the vendor is actually maintaining control effectiveness or compliance over time. Waiting for vendor self-reporting of incidents is reactive and can leave the organization exposed. Effective ongoing compliance management requires independent monitoring mechanisms and scheduled reassessments, especially for high-risk vendors.
- D. Incorrect.
This is incorrect because internal audit provides independent assurance and should not be the operational owner of the third-party assessment lifecycle. Third-party risk management is typically a cross-functional process involving procurement, legal, security, privacy, compliance, and business owners, with clear accountability for onboarding, risk acceptance, remediation tracking, and continuous monitoring. Making internal audit the primary operational assessor can blur governance lines and reduce management ownership.