CRISC Certified in Risk and Information Systems ControlGovernanceMedium

A national retail chain is expanding its online presence and plans to integrate a new third-party payment gateway. During the vendor selection process, the risk management team identifies that the proposed gateway provider's data handling practices in a specific region are not fully compliant with the chain's internal data privacy policies, although they meet local regulations. Which of the following is the MOST appropriate action for the risk manager to recommend?

  1. ANegotiate with the third-party provider to align their data handling practices with the chain's more stringent internal policies.
  2. BImplement additional technical controls within the retail chain's own systems to compensate for the provider's policy deviations.
  3. CProceed with the integration, as the provider meets local regulatory requirements, and adapt the chain's internal policy for that region.
  4. DSeek an alternative payment gateway provider that fully aligns with both local regulations and the chain's internal policies.
Show answer & explanation

Correct answer: A. Negotiate with the third-party provider to align their data handling practices with the chain's more stringent internal policies.

While finding an alternative provider (C) is an option, the most appropriate initial action is to attempt to align the chosen provider's practices with the organization's internal standards, which are often more stringent than minimum regulatory requirements. This demonstrates proactive risk management and a commitment to internal governance. Adapting internal policies (A) or relying solely on internal controls (D) without addressing the third-party's practices would introduce unnecessary risk.

Why the other options are wrong

  • B. Implementing additional controls internally may mitigate some risk but does not address the fundamental misalignment in the third-party's practices.
  • C. Adapting internal policies to a third-party's lower standard is generally not good practice and can weaken the overall risk posture.
  • D. While a valid option, it's often more practical to first attempt to resolve issues with a preferred vendor before discarding them entirely.

Third-Party Risk Alignment

The process of ensuring that external vendors' and partners' risk management practices, policies, and controls align with an organization's own internal standards and risk appetite.

  • Internal policies may exceed regulatory minimums.
  • Negotiation is a key tool in third-party risk management.
  • Proactive alignment reduces overall organizational risk.

Memory trick: Always align your partners' shields to your kingdom's standards.

More Governance questions