QuestionQ967

Risk Response and Reporting

An organization requires an annual third-party attestation report from every service provider. A service provider cannot provide the required report because of recent ownership changes. What is the BEST action for the risk practitioner?

  • A Verify that an exception has been approved.
  • B Implement additional controls to mitigate the risk.
  • C Approve an exception for the report and document associated controls.
  • D Execute an independent review of the service provider.
Explanation

When a required third-party attestation report is unavailable, the resulting deviation from organizational requirements should be formally approved through the established exception process. The risk practitioner should verify that this approval is in place rather than personally approving the exception.

Community Discussion

No comments yet. Be the first to start the discussion!