Mitigating SaaS Provider Bankruptcy Risk

IT Service Management & Cloud Security
Answer Correct answer: D — Backing up the data processed by the software ensures business continuity and enables rapid migration if the SaaS provider declares bankruptcy.

Which of the following is the BEST way to mitigate the risk of services no longer being available from a bankrupt Software as a Service (SaaS) provider?

  1. Including service level agreements (SLAs) in the contract
  2. Retaining copies of the software for emergency situations
  3. Having a software escrow agreement with a third party
  4. Backing up the data processed by the software Correct Answer

Community Votes

D
50%
C
50%

50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests cloud risk mitigation by contrasting SaaS architecture limitations with traditional on-premise solutions, where the common trap is choosing software escrow despite customers lacking source code access.

This CISA question tests strategies for maintaining business continuity when a SaaS vendor faces financial failure. While some candidates debate software escrow, experts and community consensus agree that backing up critical data is the most practical and effective mitigation.

Option C (software escrow) is frequently chosen because it works for proprietary on-premise software, but it fails here since SaaS customers never receive or control the underlying application source code.

Community Discussion (5 comments)

MIMIBAK 👍 1 Selected: C
SaaS Escrow ensures customers can access, restore, or rebuild their SaaS applications and data in case of specific pre-agreed circumstances.
root8 👍 1 Selected: D
Escrow applies to software that are proprietary to the company, not SaaS apps. You can't really ask Microsoft to put OneDrive on escrow because you have a license to use it!
blehbleh 👍 1 Selected: C
This is C. A software escrow agreement ensures that they would still have access to the software and its source code in case the provider goes out of business.
SzekelyElek 👍 1 Selected: D
I think D, since it is a SaaS service. The software was never ours.
SzekelyElek 👍 1
I think D, since it is a SaaS service. The software was never ours.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Backing up critical data directly addresses the primary operational risk when a SaaS vendor becomes insolvent. Since SaaS architecture centralizes application hosting, organizations retain responsibility for data protection and portability. Implementing regular backups ensures that essential business records survive service termination, enabling immediate recovery or migration to an alternative platform. This aligns with ISACA’s guidance on cloud data governance and business continuity planning.

Why the Other Options Are Wrong

Service level agreements merely establish performance metrics during active contracts and offer zero legal leverage during insolvency proceedings. Retaining local software copies contradicts the fundamental SaaS model, where applications run exclusively on the provider’s infrastructure. Software escrow agreements require contractual source code release rights, which subscription-based SaaS customers inherently lack. Consequently, these options either misalign with cloud service definitions or fail to address actual data retention needs.

Community Comment Notes

Top-voted discussions highlight that escrow mechanisms apply to proprietary on-premise deployments, not cloud subscriptions. As contributor #2 notes, SaaS licensing grants usage rights rather than source code access, making escrow legally unenforceable. Multiple commenters reinforce that focusing on data portability rather than application ownership reflects real-world cloud risk management. This consensus directly validates why data backup remains the definitive exam answer.

Official Reference

Exam Strategy

Always distinguish between SaaS, PaaS, and IaaS ownership models before selecting risk mitigation options. In SaaS scenarios, focus exclusively on data portability and backup rather than application-level controls like source code escrow.

Frequently Asked Questions

Why isn't software escrow appropriate for SaaS?

Escrow requires sharing source code, which SaaS vendors never provide to subscribers. Customers only license usage rights, making escrow legally and technically unfeasible.

Do SLAs protect against vendor bankruptcy?

No. SLAs define uptime and performance targets during normal operations but cannot enforce service delivery once a company ceases financial existence.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide