CRISC Certified in Risk and Information Systems ControlGovernanceHard

An organization is considering outsourcing its entire IT infrastructure to a third-party managed service provider (MSP). The board has mandated that the organization must retain ultimate accountability for data security and regulatory compliance. Which of the following governance actions is MOST critical to ensure this mandate is met?

  1. AConducting a one-time security audit of the MSP's operations before signing the contract.
  2. BIncluding a clause in the contract that transfers all liability for security breaches to the MSP.
  3. CEstablishing an internal oversight committee with clear authority to monitor the MSP's performance and compliance.
  4. DRelying solely on the MSP's certifications (e.g., ISO 27001) as proof of their security posture.
Show answer & explanation

Correct answer: C. Establishing an internal oversight committee with clear authority to monitor the MSP's performance and compliance.

Retaining ultimate accountability, even when outsourcing, requires active internal governance. An oversight committee provides the continuous monitoring, enforcement, and decision-making authority necessary to ensure the MSP adheres to security and compliance requirements.

Why the other options are wrong

  • A. A one-time audit is insufficient for continuous oversight and does not address the ongoing accountability mandate.
  • B. While liability transfer clauses are important, ultimate accountability for data security and compliance often cannot be fully transferred, especially from a regulatory perspective. The organization still bears responsibility.
  • D. Certifications are a good starting point, but they are snapshots in time and do not guarantee ongoing adherence or specific compliance with the organization's unique requirements. Active oversight is still necessary.

Outsourcing Accountability Governance

The internal organizational mechanisms, such as oversight committees, established to ensure continuous monitoring, enforcement, and ultimate accountability for outsourced functions, particularly regarding critical areas like data security and regulatory compliance.

  • Accountability cannot be fully outsourced.
  • Requires active internal oversight.
  • Ensures alignment with organizational standards and regulations.

Memory trick: Outsource the work, but keep the eyes and the buck stops here.

More Governance questions