CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium
A multinational corporation uses a shared service center for its IT operations. The risk management team has identified a critical dependency on this center for disaster recovery. To ensure the center's controls are effective, the corporation requires the center to provide an annual SOC 2 Type II report. This requirement primarily supports which aspect of risk management?
- ADefining risk appetite
- BMonitoring third-party risk
- CEstablishing control ownership
- DCommunicating residual risk
Show answer & explanationAnswer & explanation
Correct answer: B. Monitoring third-party risk
Requiring a SOC 2 Type II report for a shared service center is a common practice for monitoring the effectiveness of controls at a third-party vendor, which is a key component of third-party risk management.
Why the other options are wrong
- A. Risk appetite defines the level of risk an organization is willing to accept, not how it monitors third parties.
- C. Control ownership defines who is responsible for controls, not the method of assessing third-party control effectiveness.
- D. Communicating residual risk comes after assessing risk and controls, and a SOC 2 report is an input to that assessment, not the communication itself.
Third-Party Risk Monitoring
The ongoing process of assessing and evaluating the risks introduced by external vendors, partners, or service providers.
- Involves continuous oversight
- Uses various assurance methods (e.g., audits, certifications)
- Aims to ensure third-party controls meet organizational requirements
Memory trick: Third-Party Trust: Verify, Don't just rely!