QuestionQ328

Risk Assessment

Which of the following would pose the GREATEST risk when the processing of personally identifiable information (PII) is outsourced to a vendor that uses subcontractors?

  • A The vendor's service level agreements (SLAs) are not defined.
  • B There have been no recent onsite visits to the vendor.
  • C The vendor does not have a third-party risk management program.
  • D The contract lacks a right-to-audit clause.
Explanation

A third-party risk management program is necessary for a vendor to assess, govern, and monitor subcontractors that may access or process PII. Its absence leaves downstream privacy and security controls unverified and unmanaged, creating a direct risk of improper handling or exposure of PII.

Community Discussion

No comments yet. Be the first to start the discussion!