nerdexam
Isaca

CGEIT · Question #500

Which of the following is the MOST important consideration when integrating a new vendor with an enterprise resource planning (ERP) system?

The correct answer is B. A vendor risk assessment is conducted. The most important consideration when integrating a new vendor with an ERP system is conducting a thorough vendor risk assessment.

Submitted by zhang_li· Apr 18, 2026Risk Optimization

Question

Which of the following is the MOST important consideration when integrating a new vendor with an enterprise resource planning (ERP) system?

Options

  • AIT senior management selects the vendor.
  • BA vendor risk assessment is conducted
  • CERP data mapping is approved by the enterprise architect.
  • DProcurement provides the terms of the contract.

How the community answered

(28 responses)
  • A
    29% (8)
  • B
    50% (14)
  • C
    7% (2)
  • D
    14% (4)

Why each option

The most important consideration when integrating a new vendor with an ERP system is conducting a thorough vendor risk assessment.

AIT senior management selects the vendor.

While IT senior management's involvement in vendor selection is important, it is a governance step that ideally follows or incorporates the findings of a risk assessment.

BA vendor risk assessment is conductedCorrect

Integrating a new vendor with an Enterprise Resource Planning (ERP) system introduces potential vulnerabilities regarding data access, security, and operational reliability. Conducting a comprehensive vendor risk assessment is paramount to identify, evaluate, and mitigate these potential risks, ensuring the vendor meets the organization's security and compliance standards before sensitive ERP data is exposed or integrated.

CERP data mapping is approved by the enterprise architect.

ERP data mapping approval by the enterprise architect is a technical detail and a subsequent step in the integration process, occurring after the fundamental risks associated with the vendor have been assessed.

DProcurement provides the terms of the contract.

Procurement providing contract terms is a contractual and legal step, but the specific terms related to security and risk mitigation often stem from the findings of a vendor risk assessment.

Concept tested: Vendor risk assessment for ERP integration

Topics

#Vendor Management#Risk Assessment#Third-party Risk#ERP Integration

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice