CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentHard

A manufacturing company relies heavily on a single third-party vendor for its operational technology (OT) software. The vendor recently announced a significant price increase and mandatory migration to a new, proprietary platform. This situation presents a heightened risk of being unable to switch to an alternative vendor without incurring substantial costs and operational disruption. Which type of risk does this scenario BEST describe?

  1. ARegulatory compliance risk
  2. BSupply chain risk
  3. CGeopolitical risk
  4. DVendor lock-in risk
Show answer & explanation

Correct answer: D. Vendor lock-in risk

Vendor lock-in risk specifically describes the situation where an organization becomes dependent on a single vendor for products or services and faces significant financial, technical, or operational barriers to switching to another vendor. The scenario clearly highlights the difficulty and cost of switching due to reliance on a single vendor and a proprietary platform.

Why the other options are wrong

  • A. Regulatory compliance risk relates to failing to meet laws and regulations, which is not the primary issue described.
  • B. While it involves a vendor, 'supply chain risk' is a broader term encompassing disruptions in the entire chain, not specifically the difficulty of switching a single, entrenched vendor.
  • C. Geopolitical risk pertains to political instability or international relations affecting business, which is not relevant to this scenario.

Vendor Lock-in Risk

The risk that an organization becomes so dependent on a particular vendor's products or services that it cannot easily switch to another vendor without substantial cost, effort, or disruption.

  • Increased by proprietary technologies and integration complexity.
  • Can lead to higher costs and reduced flexibility.
  • Mitigated by open standards, clear exit strategies, and multi-vendor approaches.

Memory trick: Third-Party Trap: Locked-in, Supply-Snagged, Shared-Security, Compliance-Caught.

More IT Risk Assessment questions