nerdexam
IIA

IIA-CIA-PART1 · Question #135

Which of the following is an indicator of ineffective third-party risk management?

The correct answer is B. Violations of service conditions trigger either fines or termination. Option B describes a well-designed contractual enforcement mechanism - having defined consequences (fines or termination) for service condition violations is a hallmark of effective third-party risk management, not ineffective. This is the option that does not signal a problem…

Question

Which of the following is an indicator of ineffective third-party risk management?

Options

  • ASourcing of third parties does not follow public procurement law.
  • BViolations of service conditions trigger either fines or termination.
  • CDue diligence of third parties is conducted only after contract signing.
  • DThe right-to-audit clause is limited by personal data protection regulations.

How the community answered

(18 responses)
  • A
    11% (2)
  • B
    72% (13)
  • C
    11% (2)
  • D
    6% (1)

Explanation

Option B describes a well-designed contractual enforcement mechanism - having defined consequences (fines or termination) for service condition violations is a hallmark of effective third-party risk management, not ineffective. This is the option that does not signal a problem, making it the correct answer by process of elimination. Note: the question likely intends to ask which option reflects effective management, or which is not an indicator of ineffective management.

Why the distractors are genuine red flags:

  • A - Ignoring public procurement law exposes the organization to legal liability and signals broken governance processes.
  • C - Conducting due diligence after contract signing is a critical failure: risk assessment must happen before commitments are made, not after.
  • D - An audit clause constrained by data protection law is a real-world limitation that undermines visibility into third-party compliance.

Memory tip: Think "BEFORE, LAW, AUDIT = BAD" - skipping due diligence before signing, violating procurement law, and weak audit rights are all red flags. Contractual enforcement with fines/termination (B) is what good risk management looks like.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART1 Practice