nerdexam
Isaca

CRISC · Question #214

Which stakeholder is MOST important to include when defining a risk profile during me selection process for a new third party application'?

The correct answer is C. The business process owner. When defining a risk profile for a new third-party application, the business process owner is the most crucial stakeholder due to their comprehensive understanding of the application's operational context.

Submitted by carlos_mx· Apr 18, 2026IT Risk Assessment

Question

Which stakeholder is MOST important to include when defining a risk profile during me selection process for a new third party application'?

Options

  • AThe third-party risk manager
  • BThe application vendor
  • CThe business process owner
  • DThe information security manager

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    18% (6)
  • C
    74% (25)
  • D
    3% (1)

Why each option

When defining a risk profile for a new third-party application, the business process owner is the most crucial stakeholder due to their comprehensive understanding of the application's operational context.

AThe third-party risk manager

The third-party risk manager focuses on vendor risk and contractual aspects but may lack the granular operational insight of the business process owner.

BThe application vendor

The application vendor provides technical specifications but lacks the organizational-specific business context needed for a comprehensive risk profile.

CThe business process ownerCorrect

The business process owner possesses the deepest insight into how the application will be used, its criticality to business functions, the types of data it will process, and the potential operational and business impacts of its failure or compromise, which is essential for an accurate risk profile. They can articulate the true value and sensitivity within the business context.

DThe information security manager

The information security manager is critical for security aspects but the overall risk profile also encompasses broader business, operational, and compliance risks best articulated by the business process owner.

Concept tested: Stakeholder identification for risk profiling

Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final

Topics

#Stakeholder management#Risk profiling#Third-party risk#Business process owner

Community Discussion

No community discussion yet for this question.

Full CRISC Practice