Which missing CRM contract clause is the greatest concern for PII?

Protection of Information Assets
Answer Correct answer: D — Confidentiality terms are the essential contractual safeguard for PII hosted in the third-party CRM system.

An IS auditor is reviewing the contract for a customer relationship management (CRM) system containing personal identifiable information (PII) hosted by a third party. The absence of which of the following would be the GREATEST concern regarding the contract?

  1. Right-to-audit clause
  2. Service level agreements (SLAs)
  3. System availability requirements
  4. Confidentiality terms Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests which clause directly protects PII versus which merely verifies or measures service, and the trap is picking the right-to-audit clause instead of confidentiality terms.

When a third-party-hosted CRM system contains PII, the absence of confidentiality terms is the greatest contract risk because it removes the vendor's enforceable obligation to protect sensitive data. The CISA community overwhelmingly supports option D with 86 votes.

Choosing A (right-to-audit clause) — it feels comprehensive because it enables verification of vendor controls, but without confidentiality terms there are no defined PII protection obligations to audit against in the first place.

Community Discussion (7 comments)

46080f2 👍 1 Selected: D
The absence of confidentiality terms (D) is the greatest concern because it directly jeopardizes the protection of PII, which is the core issue for a CRM system handling sensitive data. The CISA Review Manual underscores this in Chapter 5, Section 5.3.10: "Contracts with external parties should include provisions for security and privacy, including confidentiality agreements" (Page 392). Without these terms, there’s no contractual assurance of data protection, exposing the organization to legal, regulatory, and reputational risks. While a right-to-audit clause (A) is critical for oversight, its absence is less severe if confidentiality obligations exist, as it’s a means to enforce rather than define protection. SLAs (B) and availability requirements (C) are operational concerns, not directly tied to PII security.
Enig 👍 1
A. Right-to-audit clause The absence of a right-to-audit clause would be the greatest concern in this scenario. This clause allows the organization to review and verify the third party’s compliance with security, privacy, and data protection requirements, especially important for a CRM system that contains personally identifiable information (PII). Without a right-to-audit clause, the organization may have limited ability to assess whether the third party is adequately protecting PII, which could increase risks related to data breaches and regulatory non-compliance. While SLAs, availability requirements, and confidentiality terms are also important, the right-to-audit clause is critical for ensuring ongoing compliance and accountability.
blehbleh 👍 3 Selected: D
D is the correct answer. We care about the PII and the confidentiality terms which covers what is whos responsibility, to what level it needs to be protected and other things. Just because you have a right to audit clause does not mean that it meets the required standards, policies, or procedures necessary for your data that they are handling.
thusharaj 👍 1
A right-to-audit clause allows the organisation to assess the third party's security controls, compliance with legal requirements, and handling of sensitive data like PII. Without this clause, the organisation cannot verify if the third party is properly protecting PII, which could expose the organisation to legal and compliance risks.
PurpleParrot 👍 1 Selected: A
Option A because it is more comprehensive A right-to-audit clause is critical because it gives the client organization the contractual right to audit the vendor’s security controls, processes, and compliance. Without this, the client would have no way to verify that the vendor is properly securing the sensitive personal identifiable information (PII) as required. Confidentiality terms prohibit the vendor from disclosing data but don’t give the client the right to audit the vendor’s practices. Therefore, the absence of a right-to-audit clause would be the most concerning for an IS auditor reviewing this contract, as it removes the client’s ability to verify the vendor’s security and compliance through an audit. The right-to-audit is an essential safeguard for sensitive data hosted by third parties.
Vima234 👍 2 Selected: D
Since the CRM system contains personally identifiable information (PII), having clear and enforceable confidentiality terms is critical to ensuring the protection of sensitive data, the answer is option D
Hayati 👍 1
the right wnswer is D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The CRM system hosts personally identifiable information, making data confidentiality the most critical contractual protection. Confidentiality terms establish the vendor's explicit obligations to safeguard PII, define breach liability, and anchor compliance with privacy laws and regulations. Comment 3 cites the CISA Review Manual, Chapter 5, Section 5.3.10 (page 392), which states that contracts with external parties should include provisions for security and privacy, including confidentiality agreements. Without these terms, the organization has no enforceable contractual basis for demanding protection of its customer data.

Why the Other Options Are Wrong

A right-to-audit clause (A) is valuable but is only a verification mechanism — it does not itself define what must be protected or to what standard. Comment 1 makes this exact point: having an audit right does not mean the vendor meets the required standards for the data it handles. SLAs (B) and system availability requirements (C) address service performance and uptime rather than the security of sensitive data. While their absence would be a concern, it is far less severe than having no confidentiality obligations for PII at all.

Community Comment Notes

The vote distribution is decisive: 86 votes for D and no votes recorded for any other option in the tally. Comment 1 (3 likes) and Comment 2 (2 likes) both endorse D, with Comment 1 explaining why the right-to-audit argument fails. Comments 4, 5, and 6 argue for A, but this minority reasoning — that audit rights enable verification — is precisely the trap the exam exploits. Comment 3 provides the strongest evidence with a direct CISA Review Manual citation supporting confidentiality agreements in third-party contracts.

Official Reference

Exam Strategy

When a question emphasizes PII or sensitive data at a third party, first look for the clause that directly imposes protection obligations — confidentiality. Verification clauses (right-to-audit) and performance clauses (SLAs) are secondary; pick the control that protects the data itself.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide