StudyToCert

All certifications / CISA / Lessons

ISACA Certified Information Systems Auditor (CISA) 2024 job practice · Domain 2: Governance and management of IT

IT vendor management: outsourcing, contracts, right to audit and SOC reports

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Organizations increasingly rely on vendors for software, cloud services, managed operations and whole outsourced business processes. Outsourcing moves the work but not the accountability. If a payroll provider leaks employee data, the employer still answers to its staff and regulators. Vendor management, sometimes called third-party risk management, is how the organization keeps control of risks it no longer directly operates, across the whole relationship from selection to exit.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISA for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISA study plan