CGEIT · Question #655
An enterprise has well-designed procurement and vendor risk management policies that are intended to prevent biased decision-making. However, a pattern of ethical violations indicates that vendor…
The correct answer is B. Conduct a root cause analysis and remediate based on findings. When ethical violations indicate a breakdown in policy enforcement despite well-designed policies, the first step is to conduct a root cause analysis to understand why the existing policies failed.
Question
An enterprise has well-designed procurement and vendor risk management policies that are intended to prevent biased decision-making. However, a pattern of ethical violations indicates that vendor selection may have been inappropriately influenced by non-work-related incentives provided to decision makers. Which of the following should be done FIRST in response to this issue?
Options
- ARevise the procurement and vendor risk management policies.
- BConduct a root cause analysis and remediate based on findings.
- CDocument the critical success factors (CSFs) for the procurement policies.
- DEstablish and communicate strict penalties for biased vendor selection.
How the community answered
(21 responses)- A5% (1)
- B52% (11)
- C29% (6)
- D14% (3)
Why each option
When ethical violations indicate a breakdown in policy enforcement despite well-designed policies, the first step is to conduct a root cause analysis to understand why the existing policies failed.
Revising policies without understanding *why* the current ones failed might lead to ineffective changes or fail to address the underlying behavioral or enforcement issues.
Since the problem indicates a pattern of ethical violations *despite* well-designed policies, the immediate first step is to conduct a root cause analysis. This will identify *why* the existing policies were circumvented or failed to prevent the issue, allowing for targeted and effective remediation rather than simply revising policies that might already be adequate.
Documenting critical success factors (CSFs) for procurement policies is a good governance practice but does not directly address an active pattern of ethical violations.
While communicating strict penalties can be part of a solution, it's reactive and doesn't address the underlying reasons for the ethical violations, which a root cause analysis would uncover.
Concept tested: Incident response and root cause analysis
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security/incident-response
Topics
Community Discussion
No community discussion yet for this question.