CRISC Certified in Risk and Information Systems ControlGovernanceMedium

A large manufacturing company relies heavily on a complex supply chain involving numerous third-party vendors for critical components. A recent natural disaster disrupted a key supplier, causing significant production delays and financial losses. The board is now demanding improved supply chain resilience and better risk oversight. Which of the following is the MOST effective approach for the company to enhance its supply chain governance?

  1. ADiversify the supplier base by engaging multiple vendors for each critical component.
  2. BDevelop an internal emergency response plan to manage disruptions caused by supplier failures.
  3. CNegotiate more stringent contractual clauses with existing suppliers regarding disaster recovery and business continuity.
  4. DImplement a robust third-party risk management (TPRM) program that includes continuous monitoring of supplier performance and resilience.
Show answer & explanation

Correct answer: D. Implement a robust third-party risk management (TPRM) program that includes continuous monitoring of supplier performance and resilience.

A robust Third-Party Risk Management (TPRM) program provides a comprehensive and systematic approach to assess, monitor, and manage risks associated with all third-party relationships, including supply chain partners. This holistic approach ensures continuous oversight and resilience.

Why the other options are wrong

  • A. Diversification is a valid risk mitigation strategy but is only one component of broader supply chain governance, and without proper management, can introduce new complexities.
  • B. An internal emergency plan addresses the consequences of failure but does not proactively enhance the governance or resilience of the supply chain itself, which is the board's primary concern.
  • C. Contractual clauses are important, but they are reactive (enforced after an event) and represent only one aspect of proactive risk management and continuous oversight.

Third-Party Risk Management (TPRM)

A comprehensive program designed to identify, assess, manage, and monitor risks associated with all external entities (e.g., vendors, suppliers, partners) that have access to an organization's systems, data, or processes.

  • Holistic management of external risks.
  • Includes assessment, monitoring, and oversight.
  • Crucial for supply chain resilience.

Memory trick: Govern the entire chain, don't just patch a link.

More Governance questions