CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is reviewing a third-party service provider's controls. Which of the following is the MOST important clause to include in the contract to ensure the auditor can assess the provider's controls?
⚠ Common exam trap
The trap is selecting a clause that sounds protective (SLA penalties, confidentiality) when the question specifically asks about enabling the auditor to assess controls, which only a right-to-audit clause provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Right-to-audit clause
A right-to-audit clause (A) is the most important contractual provision because it grants the organization (and its auditors or regulators) the legal right to examine the service provider's controls, records, and facilities. Without it, the auditor has no contractual basis to assess the provider's control environment, making third-party risk assurance impossible. SLAs, exit strategies, and confidentiality clauses address performance, transition, and data protection respectively, but none of them enable control assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Right-to-audit clause
Why this is correct
A right-to-audit clause contractually grants the organisation and its IS auditors the authority to examine the provider's controls, evidence and processes. Without it, the provider can lawfully refuse access, so this clause directly satisfies the requirement to assess third-party controls.
- ✗
Service level agreement (SLA) with penalties
Why it's wrong here
An SLA with penalties defines performance targets and remedies; it does not grant the auditor access to the provider's premises, records or control documentation. It is tempting because SLAs are central to managing service quality, and an SLA would be the right clause where the objective is measurable performance rather than the right to assess controls.
- ✗
Exit strategy clause
Why it's wrong here
An exit strategy clause governs transition and data return at termination; it confers no audit or examination rights during the contract term. It is tempting because exit provisions are essential for avoiding vendor lock-in, and it would be the correct focus where the risk is service continuity or portability rather than control assurance.
- ✗
Confidentiality clause
Why it's wrong here
A confidentiality clause restricts disclosure of data; it grants no right to examine the provider's control environment, so the auditor could not obtain evidence. It is tempting because confidentiality is a standard contract term, and it would be the priority where the concern is protecting the client's information rather than auditing the provider.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.