nerdexam
Isaca

CRISC · Question #28

An organization has completed a risk assessment of one of its service providers. Who should be accountable for ensuring that risk responses are implemented?

The correct answer is A. IT risk practitioner. While multiple parties are involved in third-party risk management, the IT risk practitioner is accountable for ensuring that risk responses are implemented following an assessment of a service provider. This role is responsible for overseeing the risk management process, trackin

Submitted by dimitri_ru· Apr 18, 2026Risk Response and Reporting

Question

An organization has completed a risk assessment of one of its service providers. Who should be accountable for ensuring that risk responses are implemented?

Options

  • AIT risk practitioner
  • BThird -partf3ecurity team
  • CThe relationship owner
  • DLegal representation of the business

How the community answered

(17 responses)
  • A
    71% (12)
  • B
    18% (3)
  • C
    6% (1)
  • D
    6% (1)

Why each option

While multiple parties are involved in third-party risk management, the IT risk practitioner is accountable for ensuring that risk responses are implemented following an assessment of a service provider. This role is responsible for overseeing the risk management process, tracking, and verifying the execution of agreed-upon mitigation strategies.

AIT risk practitionerCorrect

The IT risk practitioner, or the individual/team assigned the overall responsibility for managing technology-related risks, is ultimately accountable for ensuring that risk responses identified during a service provider assessment are actually implemented. They are typically responsible for tracking, monitoring, and validating that the agreed-upon actions are carried out, even if the execution is delegated to others.

BThird -partf3ecurity team

The third-party security team is responsible for implementing controls within their own organization, but the *client's* IT risk practitioner is accountable for ensuring those responses are executed and effective from the client's perspective.

CThe relationship owner

The relationship owner (e.g., business owner or vendor manager) is crucial for managing the overall relationship and facilitating communication, but they may not have the specific technical expertise or direct accountability for the *implementation* of IT risk responses.

DLegal representation of the business

Legal representation of the business provides guidance on contractual obligations and legal risks but is not typically accountable for the operational implementation of technical risk responses.

Concept tested: Third-party risk response accountability

Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-39.pdf

Topics

#Risk response implementation#Accountability#IT risk practitioner#Third-party risk management

Community Discussion

No community discussion yet for this question.

Full CRISC Practice