CISA Exam · 14 min read 2026 Blueprint Verified

CISA Information Systems Acquisition & Development: Vendor Evaluation — Complete Study Guide

Rob Pfleghardt

10-year Price Waterhouse alumnus · Founder of VoraPrep · Former CPA (1987–2024) · with the VoraPrep Editorial Team

CISA Information Systems Acquisition & Development: Vendor Evaluation — Complete Study Guide

Key Takeaways

  • Exam / Credential: Certified Information Systems Auditor (CISA) by ISACA.
  • Domain Focus: Domain 3: Information Systems Acquisition, Development, and Implementation.
  • Core Skill Tested: Assessing the adequacy of vendor selection, management, and risk mitigation processes from an IS auditor's perspective.
  • Auditor's Mindset: Evaluate if management's due diligence and controls sufficiently protect assets and meet compliance, focusing on risk adequacy.
  • Key Challenge: Candidates often think like project managers instead of independent IS auditors assessing process soundness and control.

The biggest mistake candidates make with CISA vendor evaluation isn't forgetting the steps in an RFP—it's a failure to apply the auditor's mindset. You might know what due diligence is, but the exam demands you assess the adequacy of management's process to mitigate risk, not just check a box.

Quick answer

CISA Vendor Evaluation tests your ability to assess an organization’s process for selecting and managing third-party providers. The key is to evaluate if management's due diligence, contractual protections, and risk assessments are sufficient to protect the organization's assets and meet compliance obligations, focusing on risk and control adequacy.

Key facts

  • Exam / Credential: Certified Information Systems Auditor (CISA) by ISACA.
  • Domain Focus: Domain 3: Information Systems Acquisition, Development, and Implementation.
  • Core Skill Tested: Assessing the adequacy of vendor selection, management, and risk mitigation processes from an IS auditor's perspective.
  • Auditor's Mindset: Evaluate if management's due diligence and controls sufficiently protect assets and meet compliance, focusing on risk adequacy.
  • Key Challenge: Candidates often think like project managers instead of independent IS auditors assessing process soundness and control.

Why Does Vendor Evaluation Trip Up So Many CISA Candidates?

Vendor evaluation, a core part of Domain 3 (Information Systems Acquisition, Development, and Implementation), isn't just about picking the cheapest software. It's about auditing the entire lifecycle of a third-party relationship to ensure it doesn't introduce unacceptable risk.

The CISA exam exploits a common blind spot: candidates often think like a project manager, not an IS auditor. A project manager's goal is to get the project done on time and on budget. An auditor's goal is to provide independent assurance that the process used to select and manage that vendor is sound, controlled, and aligned with the organization's risk appetite.

Free 5-Min Diagnostic

Studying for CISA CISA3? Benchmark your score in 5 minutes.

Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.

You'll face scenario questions that test your judgment on:

  • Requirements Definition: Were security and compliance needs defined before looking at vendors?
  • Due Diligence: Was the vendor's security posture, financial stability, and operational capability properly vetted?
  • Contractual Agreements: Are there explicit clauses for right-to-audit, data ownership, and a clean exit strategy?
  • Ongoing Monitoring: Is there a process to ensure the vendor remains compliant and secure after the contract is signed?

The wrong answer is almost always the one that prioritizes project deadlines or features over risk mitigation. Your job is to spot the control gap. Ready to see if you can spot them? Try VoraPrep's free CISA practice questions and test your auditor's mindset.

The Auditor's Mindset vs. Management's Mindset: The Core 'Aha' Moment

The single most important shift you can make is understanding the difference between management's responsibility and the auditor's responsibility. Management owns the vendor selection process and the associated risks. The auditor evaluates that process.

Here’s a quick-reference table to drill this distinction into your brain.

Area of FocusManagement's Responsibility (The Project Manager)IS Auditor's Responsibility
Primary GoalSelect a vendor that meets functional needs, budget, and timeline.Provide assurance that the selection process is controlled and mitigates risk.
Due DiligenceGathers vendor documents (e.g., SOC reports, financials).Assesses if the due diligence performed was sufficient for the level of risk.
ContractsNegotiates terms to get the best price and features.Reviews the contract for critical clauses (right-to-audit, SLAs, exit strategy).
RiskAccepts business risks to meet project goals.Identifies and reports on unmitigated risks to senior leadership.
DecisionMakes the final vendor selection decision.Recommends improvements to the process; does not select the vendor.

Memorizing this table is less important than internalizing the mindset. On the exam, always ask yourself: "Is this action making a business decision, or is it assessing the process by which the decision is made?"

How to Audit the Vendor Lifecycle Step-by-Step

A skilled IS auditor views vendor management not as a one-time event, but as a continuous lifecycle. Here's how to apply your auditor's lens at each stage.

1. Requirements & Risk Assessment (Pre-RFP)

This is the foundation. A flawed foundation guarantees a flawed outcome.

  • Auditor's Focus: Were all critical requirements—functional, security (e.g., encryption standards), regulatory (e.g., GDPR data residency), and operational—formally documented and approved before the vendor search began? Was a formal risk assessment conducted?
  • Key Concept (Inherent vs. Residual Risk): The auditor must verify that management identified the inherent risk of outsourcing a function (e.g., the risk of a data breach if no controls existed). The entire vendor evaluation process is a control designed to reduce that risk to an acceptable residual risk. If management hasn't defined what's "acceptable," the process is flawed.
  • Rule: The auditor's primary concern here is that the requirements document forms the basis for the evaluation criteria. Without clear, risk-based requirements, any vendor selection is based on guesswork.

2. RFP & Due Diligence

This is where you verify the vendor's claims. Trust, but verify.

  • Auditor's Focus: Was the Request for Proposal (RFP) process fair and transparent? More importantly, was the due diligence on top candidates thorough? This includes reviewing:
  • Security Posture: Current SOC 2 Type II reports (not 18-month-old ones!), penetration test results, ISO 27001 certifications.
  • Financial Viability: Are they financially stable enough to support you for the life of the contract?
  • Compliance: Do they have specific attestations for regulations you must follow (e.g., HIPAA, PCI DSS)?
  • Business Continuity: Have they tested their BCP/DR plans? Can you see the results?
  • Rule: Due diligence must be proportional to the risk. For a non-critical marketing tool, a simple review might suffice. For a core banking system, the auditor expects deep, documented evidence for every category above.

3. Contract Negotiation & Critical Clauses

The contract is your only real protection when something goes wrong. "Implied" terms are worthless.

  • Auditor's Focus: Does the contract contain explicit, unambiguous clauses that protect the organization? The auditor isn't a lawyer, but they are responsible for ensuring IS-related risks are contractually mitigated.
  • Key Clauses to Verify:
  • Right to Audit: A non-negotiable clause. The auditor must confirm it specifies the scope (what can be audited), frequency (how often), and cost (who pays for the audit).
  • Service Level Agreements (SLAs): Are they specific, measurable, and tied to financial penalties? "99.9% uptime" is a start, but what about incident response times?
  • Data Ownership & Residency: The contract must state unequivocally that you own your data and specify the geographic locations where it will be stored and processed.
  • Liability & Indemnification: Who is financially responsible in the event of a breach caused by the vendor?
  • Exit Strategy: A detailed clause outlining the process and costs for migrating your data off the vendor's platform at contract termination. This prevents vendor lock-in.
  • Rule: An auditor should recommend against signing a contract for a high-risk service if these critical clauses are missing or weak.

4. Ongoing Monitoring & Termination

The work isn't done when the contract is signed. This is a continuous relationship.

  • Auditor's Focus: Does management have a formal process for Third-Party Risk Management (TPRM)? This includes periodically reviewing vendor performance against SLAs, re-evaluating their security posture (e.g., requesting annual SOC reports), and ensuring they remain compliant.
  • Rule: The auditor looks for evidence of an ongoing monitoring program. Without it, the initial due diligence becomes useless as the vendor's risk profile changes over time.

For a consolidated view of these topics, our CISA IS Acquisition, Development & Implementation Cheat Sheet (2026) can be a useful review tool.

Worked Example: Applying the Auditor's Mindset

Let's walk through a realistic CISA scenario.

---

Scenario:

An IS auditor at OmniBank is reviewing the selection process for a new cloud-based core banking system. The project team, under pressure, has chosen "CloudCore Solutions Inc." based on price and features. The auditor finds the provided SOC 2 Type II report is 18 months old and covers only a subset of relevant services. The contract draft also lacks specific clauses on data residency and a defined exit strategy for data migration. The project manager insists these are "minor details" that can be handled post-contract.

Question: What should be the IS auditor's primary recommendation to OmniBank's management?
A. Approve the selection, but recommend a more rigorous post-implementation audit of CloudCore's controls.
B. Advise management to proceed, provided a clause for data residency is added.
C. Recommend halting the selection process until a current, comprehensive SOC 2 report is obtained, data residency is finalized, and a robust exit strategy is contracted.
D. Suggest consulting with legal counsel to assess the risks of the missing contractual clauses.

---

Step-by-Step Walkthrough:
  1. Identify the Core Risks:
  • Outdated/Incomplete Assurance: The SOC 2 report is stale and incomplete. This means there is no current, independent assurance over the vendor's controls. The residual risk is unacceptably high.
  • Compliance Risk: The missing data residency clause creates significant compliance risk for a bank.
  • Operational Risk (Vendor Lock-in): The lack of an exit strategy means OmniBank could be trapped, facing huge costs and disruption if they need to leave the vendor.
  1. Analyze the Options from an Auditor's Perspective:
  • A. Approve and audit later: This is reactive. The auditor's job is to ensure risks are mitigated before they are accepted. This option accepts massive risk upfront.
  • B. Proceed with one fix: This is a classic "partial solution" trap. It addresses the compliance risk but ignores the equally critical assurance and operational risks. An auditor must take a holistic view.
  • C. Halt until critical issues are resolved: This is the only proactive option that addresses all identified high-risk items before the organization commits. It directly aligns with the auditor's primary function: ensuring due diligence is adequate and risks are managed.
  • D. Suggest legal consult: While legal is needed, this answer passes the buck. The IS auditor has a responsibility to form a recommendation based on the IS risks they've identified. The legal consult is a part of the solution, not the auditor's entire recommendation.
  1. Determine the Best Auditor Action:

The most appropriate action is to ensure the fundamental controls of due diligence and contractual protection are in place before the risk is accepted.

✓ Correct Answer:

C. Recommend halting the selection process until a current, comprehensive SOC 2 report is obtained, data residency is finalized, and a robust exit strategy is contracted.

✨ Free Domain Calculator

Calculate Your CISA Study Hours by Domain

See the exact domain-by-domain study breakdown reflecting the 2024 ISACA Job Practice weighting shifts.

Calculate CISA Study Plan →
The Tempting Wrong Answer and Why It's Wrong:

Option B is tempting because it seems pragmatic. It fixes one big problem. But the CISA exam wants the most comprehensive answer that addresses the greatest aggregate risk. An auditor who ignores a lack of security assurance and a clear exit strategy for a core banking system isn't doing their job.

Practice Questions: Test Yourself on Vendor Evaluation

The only way to master this is to practice applying the auditor's judgment. At VoraPrep, our adaptive learning engine feeds you questions that target your specific weak spots, with over 2,300 CISA-style questions in our bank.

Here are three to try now:

---

Sample Q1: During a review of the RFP process for a new cloud provider, an IS auditor notes the evaluation criteria focus heavily on cost and features. Security, compliance, and DR capabilities are listed but not weighted. What is the auditor's most appropriate action?
A. Recommend revising the RFP evaluation criteria to include explicit, risk-based weighting for security, compliance, and DR.
B. Document the weakness and recommend a full security audit of the chosen vendor after the contract is signed.
C. Advise the team to rely on the vendor's reputation and standard SLAs for security assurances.
D. Suggest the legal department add strong penalty clauses for security breaches.
Explanation:
  • Correct Answer: A. The auditor's role is to fix the process. The evaluation criteria are a key control in the selection process. Ensuring they are risk-based and properly weighted is the most effective, proactive control improvement.
  • Why others are wrong: B is reactive. C is negligent. D is a legal remedy, not a fix for a flawed selection process.

---

Sample Q2: A firm is selecting a cloud CRM provider. The leading candidate has not had a third-party security audit (e.g., SOC 2) in two years, claiming "proprietary security measures." What should the IS auditor primarily recommend?
A. Accept the vendor's explanation, given their competitive pricing.
B. Insist on obtaining a current, independent third-party security audit report before finalizing the selection.
C. Advise negotiating a higher SLA for security incidents to compensate for the lack of an audit.
D. Document the risk and plan for enhanced internal monitoring post-implementation.
Explanation:
  • Correct Answer: B. For a system with sensitive customer data, independent assurance is non-negotiable. Lack of a current report is a major red flag. The auditor must recommend that this fundamental due diligence step be completed.
  • Why others are wrong: A prioritizes cost over security. C is a weak compensating control for a fundamental lack of assurance. D is reactive and accepts an unverified, high-risk situation.

---

Sample Q3: An auditor reviewing a draft contract for a new cloud service notes the absence of an explicit data ownership clause and a clear exit strategy. The project manager claims these are "implied." What is the auditor's best course of action?
A. Insist that explicit clauses for data ownership and a comprehensive exit strategy be added to the contract before it is signed.
B. Advise the project team to get a legal opinion on whether these terms are implied.
C. Document the omission and recommend a separate agreement be drafted after signing.
D. Prioritize a review of the vendor's BCP, as service availability is a more immediate risk.
Explanation:
  • Correct Answer: A. Fundamental protections like data ownership and the right to get your data back cannot be left to implication. The auditor must recommend these be explicitly defined in the primary contract to mitigate major long-term risks.
  • Why others are wrong: B defers the auditor's responsibility. C is bad practice; these terms must be in the main contract. D ignores a critical, strategic risk in favor of a different, albeit important, operational risk.

Want to tackle more questions on this topic? We have a full set of free practice questions for CISA Domain 3 available.

How to Prepare for Vendor Evaluation Questions on Exam Day

Vendor evaluation is a major component of Domain 3, which is 19% of your exam. Expect these concepts to appear frequently.

Time Allocation

When you see a vendor scenario, slow down. Take the 90 seconds to identify your role (auditor), the core risk (e.g., compliance, security, operational), and the control gap. The answer often hinges on choosing the most proactive and comprehensive risk mitigation.

Connections to Other CISA Domains

This topic is a hub that connects to all other domains:

  • Domain 1 (Governance & Risk): TPRM is a key part of IT governance and risk management.
  • Domain 4 (Operations): SLAs, BCP/DR, and incident response are all operational concerns that must be addressed in vendor contracts.
  • Domain 5 (Protection of Information Assets): Data ownership, encryption, and privacy clauses are central to protecting assets managed by a third party.

Understanding these links is crucial. For instance, if you're studying modern development, you'll see how vendor selection for cloud platforms is a key part of our guide to Agile and DevOps for CISA.

Final Week Review Checklist

In your last week, drill these points:

  1. Auditor's Role: Can you explain the difference between the auditor's and management's role in three sentences?
  2. Critical Clauses: Name the five most critical contract clauses an auditor must look for.
  3. Due Diligence: What are the key areas of due diligence for a high-risk vendor?
  4. Lifecycle, Not Event: Remember to consider ongoing monitoring, not just the initial selection.

A structured plan can make all the difference. Many of our successful students have used our 90-day CISA study schedule to organize their final push.

Frequently asked questions

How many questions on Vendor Evaluation are on the CISA exam? While ISACA doesn't give exact counts per topic, you can expect 5-10 questions directly or indirectly testing vendor selection, due diligence, and contract review, as it is a cornerstone of the 19% allocated to Domain 3. What's the best way to study Vendor Evaluation? Focus on judgment, not just memorization. Use practice questions to train your brain to spot the control gap in a scenario and select the most appropriate auditor action, which is always focused on proactive risk mitigation. Is Vendor Evaluation tested in simulations on the CISA exam? The CISA exam consists of multiple-choice questions. However, ISACA uses complex, scenario-based questions that require you to apply knowledge in a multi-step context, which can feel like a mini-simulation. How long should I spend studying Vendor Evaluation? Allocate 10-15 hours of focused study within your overall 150-200 hour plan. Spend this time understanding the auditor's mindset, key risks, and working through dozens of practice scenarios until the thinking becomes second nature.

---

Ready to Pass Your CISA Exam? VoraPrep offers over 2,300 practice questions with detailed explanations, an adaptive learning engine that targets your weak areas, and 24/7 AI tutor support. We teach you how to think, not just what to memorize. Visit voraprep.com to get started. Start Your Free 14-day trial at voraprep.com →
⚡ Instant Knowledge Check · 1-Click Test Drive
CISA Domain 5: Protection of Information Assets

When conducting an IS audit of an enterprise cloud infrastructure environment, which of the following identity and access management (IAM) findings represents the GREATEST information security risk?

Official resources and references

RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding a CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →
Free Diagnostic Assessment

Find your exact CISA weak spots in 10 minutes.

Most candidates fail because they study blindly. Take our free 10-question diagnostic to identify your weakest blueprint topics and receive a custom 12-week study plan PDF generated instantly.

Keep reading

Free 5-min CISA diagnostic + 12-week plan PDF

Start →
CISA 1:1 Prometric Simulator

2,300+ practice questions with instant Socratic feedback