Courseiva
easyMultiple Choice

CISA Practice Question: Is selecting a vendor for a new enterprise…

An organization is selecting a vendor for a new enterprise resource planning (ERP) system. Which of the following is the MOST critical factor in the vendor selection process?

⚠ Common exam trap

The trap here is that candidates often prioritize contractual or due diligence activities (like SLAs or financial checks) over the foundational step of requirements definition, mistakenly believing that vendor evaluation can proceed without a clear, documented baseline of what the system must accomplish.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Clearly define business requirements before issuing the request for proposal (RFP).

Clearly defining business requirements before issuing the RFP is the most critical factor because it ensures that the ERP system will align with the organization's operational needs, processes, and data flows. Without a precise requirements definition, the RFP will lack the necessary evaluation criteria, leading to mismatched vendor proposals, scope creep, and potential project failure. This step directly impacts the success of the acquisition, as it forms the foundation for all subsequent vendor evaluation and contract negotiations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Negotiate service level agreements (SLAs) in the contract.

    Why it's wrong here

    SLAs are negotiated after a vendor is chosen, so they cannot determine which ERP best fits the requirements. Contractual terms address ongoing service performance and remedies; the selection decision rests on evaluating functional fit, technical architecture and total cost against the stated business needs.

  • ✗

    Check vendor references for similar projects.

    Why it's wrong here

    References confirm past delivery but cannot establish that the vendor's ERP satisfies this organisation's specific functional and integration requirements. Reference checks support due diligence on vendor capability; requirements fit remains the decisive selection criterion, with references used to validate claims afterwards.

  • ✓

    Clearly define business requirements before issuing the request for proposal (RFP).

    Why this is correct

    Defining business requirements first ensures the RFP reflects organisational needs, enabling objective vendor comparison against functional fit. Without this, evaluation criteria become arbitrary and the chosen ERP may fail to support core processes, making requirements definition the critical prerequisite.

  • ✗

    Evaluate vendor financial stability.

    Why it's wrong here

    Financial stability matters, but it does not demonstrate that the ERP meets the organisation's functional and integration requirements, which drive selection. Vendor viability is assessed during due diligence, typically as a risk check, rather than being the decisive criterion when comparing competing ERP products.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.