mediumMultiple Choice
CRISC Practice Question: Uses a third-party vendor for payment processing
An organization uses a third-party vendor for payment processing. The vendor's latest SOC 2 report shows a significant control exception in logical access. What is the BEST way to monitor the effectiveness of the compensating controls the vendor has implemented?
⚠ Common exam trap
Many exam-takers confuse contractual remedies (like liability clauses or penalties) with actual control monitoring, but CRISC emphasizes that monitoring requires direct verification of control effectiveness, not just legal or financial agreements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Obtain the vendor's remediation plan and schedule a follow-up assessment to verify the compensating controls.
The most effective way to monitor compensating controls is to obtain the vendor's remediation plan and schedule a follow-up assessment. This allows the organization to verify that the compensating controls are operating effectively, which is a key activity in the Risk and Control Monitoring and Reporting domain. Simply accepting risk or adding contractual clauses does not provide ongoing assurance that the controls are working as intended.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk and apply a monetary penalty to the vendor.
Why it's wrong here
Paying a penalty neither verifies nor improves the vendor's logical access controls, and risk acceptance leaves the exception unmonitored. Monitoring compensating controls requires evidence such as independent audit reports, control testing results or attestations. Penalties belong in contract remedies, appropriate when the vendor repeatedly breaches agreed service levels.
- ✗
Immediately terminate the vendor contract and switch to a new payment processor.
Why it's wrong here
Termination removes visibility of the vendor's remediation and disrupts payment processing without confirming whether compensating controls work. Monitoring effectiveness requires ongoing evidence — updated SOC 2 reports, control testing or right-to-audit reviews. Switching processors is the correct response when the vendor refuses remediation or residual risk exceeds the organisation's tolerance.
- ✗
Request the vendor to include a clause in the contract that holds them liable for any breaches.
Why it's wrong here
Contractual liability clauses allocate financial risk after a breach; they generate no evidence about whether the vendor's compensating controls actually operate. Monitoring requires ongoing assurance artefacts, such as a bridge letter or control testing results. Liability clauses suit procurement negotiations where financial recourse is the objective, not control-effectiveness monitoring.
- ✓
Obtain the vendor's remediation plan and schedule a follow-up assessment to verify the compensating controls.
Why this is correct
Obtaining the remediation plan and scheduling a follow-up assessment directly verifies that the vendor's compensating controls operate effectively after the logical access exception. This tests the controls rather than relying on the vendor's assertions, satisfying ongoing third-party risk monitoring.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.