Which missing CRM contract clause is the greatest concern for PII?
An IS auditor is reviewing the contract for a customer relationship management (CRM) system containing personal identifiable information (PII) hosted by a third party. The absence of which of the following would be the GREATEST concern regarding the contract?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests which clause directly protects PII versus which merely verifies or measures service, and the trap is picking the right-to-audit clause instead of confidentiality terms.
When a third-party-hosted CRM system contains PII, the absence of confidentiality terms is the greatest contract risk because it removes the vendor's enforceable obligation to protect sensitive data. The CISA community overwhelmingly supports option D with 86 votes.
Choosing A (right-to-audit clause) — it feels comprehensive because it enables verification of vendor controls, but without confidentiality terms there are no defined PII protection obligations to audit against in the first place.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The CRM system hosts personally identifiable information, making data confidentiality the most critical contractual protection. Confidentiality terms establish the vendor's explicit obligations to safeguard PII, define breach liability, and anchor compliance with privacy laws and regulations. Comment 3 cites the CISA Review Manual, Chapter 5, Section 5.3.10 (page 392), which states that contracts with external parties should include provisions for security and privacy, including confidentiality agreements. Without these terms, the organization has no enforceable contractual basis for demanding protection of its customer data.Why the Other Options Are Wrong
A right-to-audit clause (A) is valuable but is only a verification mechanism — it does not itself define what must be protected or to what standard. Comment 1 makes this exact point: having an audit right does not mean the vendor meets the required standards for the data it handles. SLAs (B) and system availability requirements (C) address service performance and uptime rather than the security of sensitive data. While their absence would be a concern, it is far less severe than having no confidentiality obligations for PII at all.Community Comment Notes
The vote distribution is decisive: 86 votes for D and no votes recorded for any other option in the tally. Comment 1 (3 likes) and Comment 2 (2 likes) both endorse D, with Comment 1 explaining why the right-to-audit argument fails. Comments 4, 5, and 6 argue for A, but this minority reasoning — that audit rights enable verification — is precisely the trap the exam exploits. Comment 3 provides the strongest evidence with a direct CISA Review Manual citation supporting confidentiality agreements in third-party contracts.Official Reference
Exam Strategy
When a question emphasizes PII or sensitive data at a third party, first look for the clause that directly imposes protection obligations — confidentiality. Verification clauses (right-to-audit) and performance clauses (SLAs) are secondary; pick the control that protects the data itself.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →