Answer: D - Third-party Risk Management (TPRM) is most effective when tackled as an organization-wide practice because all employees, including department manager and executive management should be educated about vendor risks and what to look for in selecting vendors. Each person within the organization who relies on vendor-provided services plays a part. By informing and educating staff, there is an improved likelihood that employees will select and rely on compliant vendors.