An organization's TPRM policy requires annual reassessment of all vendors. A critical vendor has undergone a significant merger mid-year. What action should the risk team take?
-
A
Wait for the scheduled annual review since the policy does not allow exceptions
-
B
Trigger an out-of-cycle risk reassessment due to the material change in the vendor's profile
-
C
Request only an updated vendor questionnaire without reassessing risk ratings
-
D
Reduce oversight since larger merged entities are generally more stable