CCSP Legal, Risk, and Compliance Practice Question
A multinational bank uses a cloud provider for a system that processes customer transactions. A regulator asks the bank to demonstrate that it maintains effective control over the data and can meet its legal obligations even if the provider fails. Which activity best demonstrates that the bank has retained accountability for the outsourced processing?
⚠ Common exam trap
The trap here is equating contractual liability transfer, such as an indemnification clause, with regulatory accountability, which remains with the regulated entity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Maintaining a documented risk assessment and control mapping that assigns responsibility for each obligation
Retaining accountability requires documented governance: a risk assessment covering the outsourced activity, a mapping of legal obligations to controls, and clear assignment of responsibility between the bank and provider. This evidence shows the regulator that the bank governs the relationship and can meet its obligations even if the provider fails. Assurance reports, indemnities, and data localization support the program but do not replace accountability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Relying on the provider's SOC 2 Type II report as the sole evidence of control effectiveness
Why it's wrong here
A SOC 2 Type II report provides independent assurance over the provider's controls, but relying on it alone does not demonstrate the bank's own accountability. The bank remains responsible for determining whether those controls meet its regulatory obligations, mapping them to its risk profile, and supplementing them where gaps exist. Sole reliance shifts assurance without retaining governance.
- ✓
Maintaining a documented risk assessment and control mapping that assigns responsibility for each obligation
Why this is correct
Accountability means the bank can show it identified its legal and regulatory obligations, assessed the risks of outsourcing, and mapped each control to a responsible party. This documentation demonstrates that the bank governs the relationship rather than delegating responsibility. It also supports regulatory examination because the bank can evidence continuous oversight and remediation.
- ✗
Requiring the provider to store all data in the bank's home country to simplify oversight
Why it's wrong here
Data localization can reduce certain legal complexities, but it does not by itself demonstrate accountability for processing. The bank still must govern access, monitor controls, and ensure compliance with applicable rules. Residency is one control among many and cannot substitute for a broader governance and risk management framework.
- ✗
Transferring all security responsibility to the provider through an indemnification clause
Why it's wrong here
Indemnification allocates financial liability but does not transfer regulatory accountability. The bank remains answerable to its regulator for the outsourced activity regardless of contractual indemnities. Regulators consistently hold regulated entities responsible for third-party risk, so shifting blame through a clause does not satisfy the expectation to demonstrate effective control.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.