CRISC Certified in Risk and Information Systems ControlGovernanceMedium

An organization is migrating its critical customer database to a new cloud provider. During the vendor selection process, the procurement team focuses heavily on cost and service level agreements (SLAs). The risk committee, however, raises concerns about the cloud provider's data sovereignty policies and their incident response capabilities. This disparity indicates a gap in the organization's enterprise risk management (ERM) program concerning which of the following?

  1. AThe effectiveness of IT asset management.
  2. BThe maturity of business continuity planning.
  3. CThe definition of the organization's risk appetite.
  4. DThe integration of risk criteria into procurement processes.
Show answer & explanation

Correct answer: D. The integration of risk criteria into procurement processes.

The scenario shows that the procurement team is not adequately considering risk criteria, such as data sovereignty and incident response, during the vendor selection process. This indicates a failure to integrate ERM principles into procurement, leading to potential unaddressed risks.

Why the other options are wrong

  • A. IT asset management deals with tracking and managing IT assets post-acquisition, not primarily with the risk considerations during the procurement phase.
  • B. Business continuity planning is related to resilience, but the immediate problem is the failure to assess and incorporate risks during the selection of a critical service provider, which precedes BCP implementation for that provider.
  • C. While risk appetite is foundational, the issue here is not that the appetite is undefined, but that risk considerations are not being applied effectively in a specific operational process (procurement).

Risk-Informed Procurement

The process of integrating enterprise risk management (ERM) principles and criteria into all stages of an organization's procurement lifecycle.

  • Ensures risk considerations are part of vendor selection and contract negotiation.
  • Helps mitigate supply chain and third-party risks.
  • Aligns procurement decisions with organizational risk appetite and compliance requirements.

Memory trick: Buy Smart, Risk Aware, No Regrets.

More Governance questions