ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 519 - CGEIT discussion

Report
Export

An enterprise has decided to use third-party software for a business process which is hosted and supported by the same third party. The BEST way to provide quality of service oversight would be to establish a process:

A.

for robust change management.

Answers
A.

for robust change management.

B.

for periodic service provider audits.

Answers
B.

for periodic service provider audits.

C.

for enterprise architecture (EA) updates.

Answers
C.

for enterprise architecture (EA) updates.

D.

to qualify service providers.

Answers
D.

to qualify service providers.

Suggested answer: B

Explanation:

A periodic service provider audit is a process of conducting an independent and objective assessment of the service provider's performance, quality, compliance, and security in relation to the agreed service level agreement (SLA) and the enterprise's expectations and requirements. A periodic service provider audit can help provide quality of service oversight by:

Verifying and validating the service provider's claims and credentials, and ensuring that they meet the contractual obligations and standards

Identifying and evaluating the strengths, weaknesses, opportunities, and threats of the service provider's services, processes, and controls

Detecting and reporting any issues, gaps, or risks that may affect the quality of service delivery or the enterprise's objectives and value

Recommending and implementing corrective and preventive actions to address and resolve the issues, gaps, or risks

Monitoring and measuring the outcomes and effectiveness of the corrective and preventive actions, and ensuring their alignment with the SLA

According to the CGEIT Review Manual 20221, ''Service provider audits are a key mechanism for ensuring that service providers are meeting their contractual obligations and delivering value to the enterprise. Service provider audits should be conducted periodically or as needed to assess the performance, quality, compliance, and security of the service provider's services, processes, and controls.''

According to the ISACA article on IT Outsourcing: Audit Considerations2, ''IT outsourcing audit is a process of examining and evaluating the IT outsourcing arrangements between an enterprise and its service providers. IT outsourcing audit aims to provide assurance that the IT outsourcing arrangements are aligned with the enterprise's strategy, objectives, and risk appetite; that the service providers are delivering the expected services in accordance with the SLAs; that the service providers are complying with the applicable laws, regulations, and standards; and that the service providers are managing and mitigating the IT outsourcing risks effectively.''

According to the PwC article on Service Provider Audits3, ''Service provider audits are an essential tool for organizations to gain insight into their service providers' operations, controls, risks, and compliance status. Service provider audits can help organizations ensure that their service providers are meeting their expectations and obligations; identify any areas of improvement or concern; enhance their relationship and communication with their service providers; and optimize their IT outsourcing strategy.''

asked 18/11/2024
Lebogang Aphane
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first