nerdexam
Isaca

CRISC · Question #462

Which of the following is MOST important requirement to include in a Software as a Service (SaaS) vendor contract to ensure data is protected?

The correct answer is B. The vendor must host data in a specific geographic location. Specifying data hosting location in a SaaS contract is crucial for complying with data residency requirements and regulatory obligations.

Submitted by yasin.bd· Apr 18, 2026Governance

Question

Which of the following is MOST important requirement to include in a Software as a Service (SaaS) vendor contract to ensure data is protected?

Options

  • AThe vendor must provide periodic independent assurance reports.
  • BThe vendor must host data in a specific geographic location.
  • CThe vendor must be held liable for regulatory fines for failure to protect data.
  • DThe vendor must participate in an annual vendor performance review.

How the community answered

(30 responses)
  • A
    33% (10)
  • B
    43% (13)
  • C
    7% (2)
  • D
    17% (5)

Why each option

Specifying data hosting location in a SaaS contract is crucial for complying with data residency requirements and regulatory obligations.

AThe vendor must provide periodic independent assurance reports.

While periodic independent assurance reports (like SOC 2) are important for demonstrating security posture, they do not directly dictate or enforce where data is stored for compliance purposes.

BThe vendor must host data in a specific geographic location.Correct

Requiring the vendor to host data in a specific geographic location is often a critical contractual requirement to comply with data residency laws and regulatory mandates (e.g., GDPR, CCPA) that dictate where personal or sensitive data must be stored and processed. This directly impacts data protection by ensuring legal compliance and potentially limiting exposure to foreign jurisdiction laws.

CThe vendor must be held liable for regulatory fines for failure to protect data.

Holding the vendor liable for regulatory fines is a critical contractual clause for risk transfer but does not, in itself, guarantee proactive data protection or compliance with data residency laws.

DThe vendor must participate in an annual vendor performance review.

An annual vendor performance review is a general governance practice for managing vendor relationships and service quality, but it does not directly address specific data protection requirements like residency.

Concept tested: SaaS contract data residency requirements

Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr-data-residency-requirements

Topics

#SaaS contracts#Data protection#Data residency#Regulatory compliance

Community Discussion

No community discussion yet for this question.

Full CRISC Practice