nerdexam
Isaca

CGEIT · Question #88

A healthcare enterprise that is subject to strict compliance requirements has decided to outsource several key IT services to third-party providers. Which of the following would be the BEST way to ass

The correct answer is C. Exercise the right to perform an audit.. For a healthcare enterprise outsourcing critical IT services with strict compliance needs, the best way to assess compliance and avoid reputational damage is to exercise the right to perform an independent audit. This allows for direct verification of controls and adherence to re

Submitted by packet_pusher· Apr 18, 2026Governance of Enterprise IT

Question

A healthcare enterprise that is subject to strict compliance requirements has decided to outsource several key IT services to third-party providers. Which of the following would be the BEST way to assess compliance and avoid reputational damage?

Options

  • ARequire quarterly reports from the providers demonstrating compliance.
  • BRequire documentation that the providers have adequate controls in place.
  • CExercise the right to perform an audit.
  • DImpose monetary penalties for noncompliance.

How the community answered

(43 responses)
  • A
    9% (4)
  • B
    5% (2)
  • C
    84% (36)
  • D
    2% (1)

Why each option

For a healthcare enterprise outsourcing critical IT services with strict compliance needs, the best way to assess compliance and avoid reputational damage is to exercise the right to perform an independent audit. This allows for direct verification of controls and adherence to regulatory requirements.

ARequire quarterly reports from the providers demonstrating compliance.

Requiring quarterly reports is helpful for ongoing monitoring, but reports are self-attestations and may not provide the same level of independent verification as an audit, especially in high-risk, regulated environments.

BRequire documentation that the providers have adequate controls in place.

Requiring documentation of adequate controls is a necessary foundational step, but simply having documented controls does not guarantee they are implemented effectively or operating as intended.

CExercise the right to perform an audit.Correct

Exercising the right to perform an audit provides the most robust and direct assurance of compliance. An independent audit allows the healthcare enterprise to directly verify that the third-party provider's controls and processes meet stringent compliance requirements and that sensitive data is handled appropriately, which is crucial for avoiding reputational damage.

DImpose monetary penalties for noncompliance.

Imposing monetary penalties for noncompliance is a corrective measure and a contractual deterrent, but it occurs *after* noncompliance has been identified and damage may have already occurred, rather than proactively assessing and preventing it.

Concept tested: Third-party risk and compliance assessment

Source: https://www.isaca.org/resources/isaca-journal/issues/2021/volume-2/securing-the-third-party-risk-management-process

Topics

#Outsourcing management#Compliance assessment#Third-party risk management#IT audit

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice