CAS-001 · Question #51
A bank has just outsourced the security department to a consulting firm, but retained the security architecture group. A few months into the contract the bank discovers that the consulting firm has…
The correct answer is B. Ensure the consulting firm has service agreements with the sub-contractor; if the agreement does. In vendor/third-party risk management, the primary contract holder (the consulting firm) remains responsible for service delivery and compliance. The bank's legal and service protections flow through the prime contract with the consulting firm - not through a direct…
Question
A bank has just outsourced the security department to a consulting firm, but retained the security architecture group. A few months into the contract the bank discovers that the consulting firm has sub-contracted some of the security functions to another provider. Management is pressuring the sourcing manager to ensure adequate protections are in place to insulate the bank from legal and service exposures. Which of the following is the MOST appropriate action to take?
Options
- ADirectly establish another separate service contract with the sub-contractor to limit the risk exposure
- BEnsure the consulting firm has service agreements with the sub-contractor; if the agreement does
- CLog it as a risk in the business risk register and pass the risk to the consulting firm for acceptance
- DTerminate the contract immediately and bring the security department in-house again to reduce
How the community answered
(49 responses)- A8% (4)
- B45% (22)
- C31% (15)
- D16% (8)
Explanation
In vendor/third-party risk management, the primary contract holder (the consulting firm) remains responsible for service delivery and compliance. The bank's legal and service protections flow through the prime contract with the consulting firm - not through a direct relationship with sub-contractors. The correct action is to ensure the consulting firm has appropriate service agreements with the sub-contractor that mirror or align with the bank's requirements (e.g., security standards, SLAs, audit rights, data handling). If those agreements are not in place or are deficient, the bank should require remediation through the prime contractor. Option A creates a tangled, dual-contract liability and undermines the prime contractor's accountability. Option C merely documents the risk without resolving it. Option D is a drastic, costly reaction when a contractual resolution is available.
Topics
Community Discussion
No community discussion yet for this question.