Courseiva

CCSP Legal, Risk, and Compliance Practice Question

A multinational bank uses a cloud provider for a system that processes customer transactions. A regulator asks the bank to demonstrate that it maintains effective control over the data and can meet its legal obligations even if the provider fails. Which activity best demonstrates that the bank has retained accountability for the outsourced processing?

⚠ Common exam trap

The trap here is equating contractual liability transfer, such as an indemnification clause, with regulatory accountability, which remains with the regulated entity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Maintaining a documented risk assessment and control mapping that assigns responsibility for each obligation

Retaining accountability requires documented governance: a risk assessment covering the outsourced activity, a mapping of legal obligations to controls, and clear assignment of responsibility between the bank and provider. This evidence shows the regulator that the bank governs the relationship and can meet its obligations even if the provider fails. Assurance reports, indemnities, and data localization support the program but do not replace accountability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Relying on the provider's SOC 2 Type II report as the sole evidence of control effectiveness

    Why it's wrong here

    A SOC 2 Type II report provides independent assurance over the provider's controls, but relying on it alone does not demonstrate the bank's own accountability. The bank remains responsible for determining whether those controls meet its regulatory obligations, mapping them to its risk profile, and supplementing them where gaps exist. Sole reliance shifts assurance without retaining governance.

  • ✓

    Maintaining a documented risk assessment and control mapping that assigns responsibility for each obligation

    Why this is correct

    Accountability means the bank can show it identified its legal and regulatory obligations, assessed the risks of outsourcing, and mapped each control to a responsible party. This documentation demonstrates that the bank governs the relationship rather than delegating responsibility. It also supports regulatory examination because the bank can evidence continuous oversight and remediation.

  • ✗

    Requiring the provider to store all data in the bank's home country to simplify oversight

    Why it's wrong here

    Data localization can reduce certain legal complexities, but it does not by itself demonstrate accountability for processing. The bank still must govern access, monitor controls, and ensure compliance with applicable rules. Residency is one control among many and cannot substitute for a broader governance and risk management framework.

  • ✗

    Transferring all security responsibility to the provider through an indemnification clause

    Why it's wrong here

    Indemnification allocates financial liability but does not transfer regulatory accountability. The bank remains answerable to its regulator for the outsourced activity regardless of contractual indemnities. Regulators consistently hold regulated entities responsible for third-party risk, so shifting blame through a clause does not satisfy the expectation to demonstrate effective control.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.