CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium

A multinational corporation uses a shared service center for its IT operations. The risk management team has identified a critical dependency on this center for disaster recovery. To ensure the center's controls are effective, the corporation requires the center to provide an annual SOC 2 Type II report. This requirement primarily supports which aspect of risk management?

  1. ADefining risk appetite
  2. BMonitoring third-party risk
  3. CEstablishing control ownership
  4. DCommunicating residual risk
Show answer & explanation

Correct answer: B. Monitoring third-party risk

Requiring a SOC 2 Type II report for a shared service center is a common practice for monitoring the effectiveness of controls at a third-party vendor, which is a key component of third-party risk management.

Why the other options are wrong

  • A. Risk appetite defines the level of risk an organization is willing to accept, not how it monitors third parties.
  • C. Control ownership defines who is responsible for controls, not the method of assessing third-party control effectiveness.
  • D. Communicating residual risk comes after assessing risk and controls, and a SOC 2 report is an input to that assessment, not the communication itself.

Third-Party Risk Monitoring

The ongoing process of assessing and evaluating the risks introduced by external vendors, partners, or service providers.

  • Involves continuous oversight
  • Uses various assurance methods (e.g., audits, certifications)
  • Aims to ensure third-party controls meet organizational requirements

Memory trick: Third-Party Trust: Verify, Don't just rely!

More Risk Response and Reporting questions