IIA-CIA-PART1 · Question #135
Which of the following is an indicator of ineffective third-party risk management?
The correct answer is B. Violations of service conditions trigger either fines or termination. Option B describes a well-designed contractual enforcement mechanism - having defined consequences (fines or termination) for service condition violations is a hallmark of effective third-party risk management, not ineffective. This is the option that does not signal a problem…
Question
Which of the following is an indicator of ineffective third-party risk management?
Options
- ASourcing of third parties does not follow public procurement law.
- BViolations of service conditions trigger either fines or termination.
- CDue diligence of third parties is conducted only after contract signing.
- DThe right-to-audit clause is limited by personal data protection regulations.
How the community answered
(18 responses)- A11% (2)
- B72% (13)
- C11% (2)
- D6% (1)
Explanation
Option B describes a well-designed contractual enforcement mechanism - having defined consequences (fines or termination) for service condition violations is a hallmark of effective third-party risk management, not ineffective. This is the option that does not signal a problem, making it the correct answer by process of elimination. Note: the question likely intends to ask which option reflects effective management, or which is not an indicator of ineffective management.
Why the distractors are genuine red flags:
- A - Ignoring public procurement law exposes the organization to legal liability and signals broken governance processes.
- C - Conducting due diligence after contract signing is a critical failure: risk assessment must happen before commitments are made, not after.
- D - An audit clause constrained by data protection law is a real-world limitation that undermines visibility into third-party compliance.
Memory tip: Think "BEFORE, LAW, AUDIT = BAD" - skipping due diligence before signing, violating procurement law, and weak audit rights are all red flags. Contractual enforcement with fines/termination (B) is what good risk management looks like.
Community Discussion
No community discussion yet for this question.