Courseiva

CRISC Risk Response and Reporting Practice Question

A risk manager is designing a third-party risk management program. Which THREE factors should be considered when determining the risk tier of a vendor?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The type of data the vendor will access

Option B is correct because the type of data the vendor will access directly determines the potential impact of a breach — vendors handling regulated data such as PII, PHI, or cardholder data (PCI DSS scope) warrant a higher risk tier than those with no data access. Option D is correct because a vendor's security certifications and audit results (e.g., SOC 2 Type II, ISO/IEC 27001, PCI DSS AOC) provide objective evidence of the maturity and effectiveness of its control environment, which is a core input to tiering. Option E is correct because the criticality of the service provided reflects business impact — an outage or compromise of a vendor supporting a critical business process or system causes far greater operational and financial harm than a non-essential service. Option A does not belong because a vendor's physical location alone is not a primary tiering factor; geography may inform jurisdictional or regulatory considerations but does not by itself indicate risk level. Option C does not belong because annual revenue is a financial size indicator, not a measure of the risk the vendor poses to the organization's data, systems, or operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The vendor's physical location

    Why it's wrong here

    Physical location alone does not determine inherent risk; tiering hinges on data access, criticality and control maturity. It is tempting because jurisdiction affects regulatory exposure and breach notification duties, so location would matter when assessing legal or data-residency obligations rather than the vendor's overall risk tier.

  • ✓

    The type of data the vendor will access

    Why this is correct

    Data sensitivity drives inherent risk: vendors accessing confidential, personal or regulated data create higher exposure from breach or misuse. This determines the depth of due diligence and contractual controls applied, directly informing the vendor's risk tier.

  • ✗

    The vendor's annual revenue

    Why it's wrong here

    Annual revenue measures vendor size, not the risk the vendor poses; tiering depends on data sensitivity, service criticality and access privileges. It is tempting because financial standing indicates viability and concentration risk, so revenue would be relevant when assessing a vendor's financial stability rather than its inherent risk tier.

  • ✓

    The vendor's security certifications and audit results

    Why this is correct

    Security certifications and audit results provide independent assurance over a vendor's control environment, directly satisfying the due-diligence evidence needed to assign a risk tier. Unlike self-attested questionnaires, third-party audit opinions (for example SOC 2) verify control design and operating effectiveness, so vendors handling sensitive data or Microsoft Entra ID federated access can be tiered according to validated, not claimed, risk.

  • ✓

    The criticality of the service provided

    Why this is correct

    Criticality determines how severely business operations, revenue or compliance would suffer if the vendor failed, directly driving the risk tier. A vendor supporting a core payment platform warrants higher scrutiny than one supplying office stationery, satisfying the stem's requirement to rank vendors by inherent risk exposure.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.