nerdexam
Isaca

CDPSE · Question #119

Which of the following is BEST used to validate compliance with agreed-upon service levels established with a third party that processes personal data?

The correct answer is D. Contractual right to audit. A contractual right to audit gives the organization the legal authority to directly inspect and verify a third party's actual practices, controls, and compliance with agreed-upon service levels - including data privacy obligations. KRIs (A) measure risk thresholds and KPIs (B)…

Privacy Governance

Question

Which of the following is BEST used to validate compliance with agreed-upon service levels established with a third party that processes personal data?

Options

  • AKey risk indicators (KRIs)
  • BKey performance indicators (KPIS)
  • CIndustry benchmarks
  • DContractual right to audit

How the community answered

(61 responses)
  • A
    25% (15)
  • B
    5% (3)
  • C
    11% (7)
  • D
    59% (36)

Explanation

A contractual right to audit gives the organization the legal authority to directly inspect and verify a third party's actual practices, controls, and compliance with agreed-upon service levels - including data privacy obligations. KRIs (A) measure risk thresholds and KPIs (B) measure performance metrics, but both rely on data the third party self-reports, providing no independent verification. Industry benchmarks (C) compare against general standards, not the specific contractual obligations. Only a right to audit enables objective, enforceable validation of compliance with negotiated terms.

Topics

#Third-party risk management#Contractual audits#Service level agreements (SLAs)#Compliance validation

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice