IIA-CIA-Part3 Exam QuestionsBrowse all questions from this exam

IIA-CIA-Part3 Exam - Question 157


An organization is considering outsourcing its IT services, and the internal auditor is assessing the related risks. The auditor grouped the related risks into three categories:

- Risks specific to the organization itself.

- Risks specific to the service provider.

- Risks shared by both the organization and the service provider.

Which of the following risks should the auditor classify as specific to the service provider?

Show Answer
Correct Answer: BC

When assessing risks specific to the service provider in an IT outsourcing agreement, the most relevant aspect is the provider's internal management and capabilities. Inadequate staffing at the service provider is a risk that is specific to them because it directly concerns their ability to deliver the agreed services effectively. Other options, such as unexpected increases in outsourcing costs, loss of data privacy, and violation of contractual terms, either involve shared responsibility or do not fall squarely on the provider's management alone.

Discussion

3 comments
Sign in to comment
CrazyhydraOption: C
Sep 28, 2023

the correct answer is C

KonradKOption: C
Mar 11, 2024

Agree should be C

ZoeLeeOption: C
Mar 21, 2024

it's C