nerdexam
Isaca

CGEIT · Question #655

An enterprise has well-designed procurement and vendor risk management policies that are intended to prevent biased decision-making. However, a pattern of ethical violations indicates that vendor…

The correct answer is B. Conduct a root cause analysis and remediate based on findings. When ethical violations indicate a breakdown in policy enforcement despite well-designed policies, the first step is to conduct a root cause analysis to understand why the existing policies failed.

Submitted by deeparc· Apr 18, 2026Governance of Enterprise IT

Question

An enterprise has well-designed procurement and vendor risk management policies that are intended to prevent biased decision-making. However, a pattern of ethical violations indicates that vendor selection may have been inappropriately influenced by non-work-related incentives provided to decision makers. Which of the following should be done FIRST in response to this issue?

Options

  • ARevise the procurement and vendor risk management policies.
  • BConduct a root cause analysis and remediate based on findings.
  • CDocument the critical success factors (CSFs) for the procurement policies.
  • DEstablish and communicate strict penalties for biased vendor selection.

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    52% (11)
  • C
    29% (6)
  • D
    14% (3)

Why each option

When ethical violations indicate a breakdown in policy enforcement despite well-designed policies, the first step is to conduct a root cause analysis to understand why the existing policies failed.

ARevise the procurement and vendor risk management policies.

Revising policies without understanding *why* the current ones failed might lead to ineffective changes or fail to address the underlying behavioral or enforcement issues.

BConduct a root cause analysis and remediate based on findings.Correct

Since the problem indicates a pattern of ethical violations *despite* well-designed policies, the immediate first step is to conduct a root cause analysis. This will identify *why* the existing policies were circumvented or failed to prevent the issue, allowing for targeted and effective remediation rather than simply revising policies that might already be adequate.

CDocument the critical success factors (CSFs) for the procurement policies.

Documenting critical success factors (CSFs) for procurement policies is a good governance practice but does not directly address an active pattern of ethical violations.

DEstablish and communicate strict penalties for biased vendor selection.

While communicating strict penalties can be part of a solution, it's reactive and doesn't address the underlying reasons for the ethical violations, which a root cause analysis would uncover.

Concept tested: Incident response and root cause analysis

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security/incident-response

Topics

#Ethical conduct#Vendor risk management#Root cause analysis#Governance effectiveness

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice