Certified in the Governance of Enterprise IT (CGEIT) — Question 285
Which of the following should be done FIRST when concerns have been identified regarding the financial viability of a potential software supplier?
Answer options
- A. Perform a risk assessment
- B. Implement an escrow agreement
- C. Include a right-to-audit clause in the contract
- D. License the intellectual property
Correct answer: A
Explanation
The correct answer is A, as performing a risk assessment allows for a thorough evaluation of the supplier's financial health before taking further actions. Options B, C, and D are reactive measures that come after identifying risks, rather than addressing concerns at the outset.