When auditing a third-party provider, it is MOST important to ensure:
A third-party audit should verify that risks identified in the risk assessment have been addressed through appropriate controls, mitigation, acceptance, or other risk-treatment actions. The other practices support ongoing vendor oversight but do not directly demonstrate that identified risks have been resolved.
Community Discussion