nerdexam
Isaca

CGEIT · Question #653

Which of the following would BEST enable an enterprise to ensure selected cloud vendors meet stringent regulatory requirements?

The correct answer is D. Third-party audit reports. To ensure cloud vendors meet stringent regulatory requirements, obtaining third-party audit reports (e.g., SOC 2, ISO 27001) is the best method as they provide independent verification of a vendor's controls.

Submitted by olafpl· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following would BEST enable an enterprise to ensure selected cloud vendors meet stringent regulatory requirements?

Options

  • AStage gate reviews
  • BRisk assessment
  • CInternal audit report
  • DThird-party audit reports

How the community answered

(46 responses)
  • A
    9% (4)
  • B
    17% (8)
  • C
    4% (2)
  • D
    70% (32)

Why each option

To ensure cloud vendors meet stringent regulatory requirements, obtaining third-party audit reports (e.g., SOC 2, ISO 27001) is the best method as they provide independent verification of a vendor's controls.

AStage gate reviews

Stage gate reviews are internal project management checkpoints and are not specifically designed to assess a vendor's ongoing regulatory compliance.

BRisk assessment

While a risk assessment is crucial for understanding potential vendor risks, it is an internal process and may not provide the independent, comprehensive evidence of regulatory compliance that a third-party audit report offers.

CInternal audit report

An internal audit report of the enterprise itself would assess the enterprise's controls over vendor management, but it would not provide direct evidence of the *vendor's* adherence to regulatory requirements.

DThird-party audit reportsCorrect

Third-party audit reports (such as SOC 2, ISO 27001, or FedRAMP assessments) provide independent verification and assurance that a cloud vendor's security, compliance, and operational controls meet stringent regulatory and industry standards. These reports offer an objective and comprehensive view of the vendor's adherence to required controls, making them the best tool for ensuring compliance.

Concept tested: Cloud vendor due diligence for compliance

Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2

Topics

#Cloud vendor management#Regulatory compliance#Third-party risk management#Assurance reports

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice