An organization has decided to use an external auditor to review the control environment of an outsourced service provider. The BEST control criteria to evaluate the provider would be based on:
A.
the service provider's existing controls.
B.
guidance provided by the external auditor.
C.
a recognized industry control framework.
D.
the organization's specific control requirements.
When an organization decides to use an external auditor to review the control environment of an outsourced service provider, the best control criteria to evaluate the provider would be based on a recognized industry control framework. C should be the answer. An external auditor will compare with industry standards.
When dealing with third party risk, the focus is typically on the controls relevant to the service(s) provided. Going with D. (The only other one that is interesting is C as you often take existing third party audit reports in the third party risk world, like a SOC2 / PCI / ISO report, as long as it covers the service being outsourced.)
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Samadev
2 months, 3 weeks agoCbtL
1 year, 7 months agoKoulyo
1 year, 7 months ago