CCCP CCCP Third-Party & Vendor Compliance 1 — Questions and Answers
Question 1: Why is third-party due diligence considered a critical component of a CCCP-level compliance program?
- Because third parties are immune from U.S. law enforcement
- Because organizations can be held liable for the misconduct of their third parties under laws like the FCPA (Correct answer)
- Because third-party contracts always require external legal counsel
- Because vendor invoices must be approved by the compliance officer
Correct answer: Because organizations can be held liable for the misconduct of their third parties under laws like the FCPA
The FCPA and other U.S. laws impose liability on companies for third-party misconduct conducted on their behalf, making due diligence essential.
Question 2: What is a 'risk-tiered' approach to third-party due diligence?
- Applying the same level of scrutiny to all vendors regardless of risk
- Calibrating the depth of due diligence based on each third party's risk profile, including geography, industry, and contract scope (Correct answer)
- Requiring all third parties to obtain independent compliance certifications
- Delegating due diligence entirely to the procurement department
Correct answer: Calibrating the depth of due diligence based on each third party's risk profile, including geography, industry, and contract scope
A risk-tiered approach allocates compliance resources proportionately, applying enhanced due diligence to high-risk third parties while streamlining reviews for low-risk ones.
Question 3: Which factor most significantly elevates the compliance risk associated with a foreign third-party agent?
- The agent charges above-market commission rates
- The agent operates in a high-corruption-index country and interacts with foreign government officials (Correct answer)
- The agent uses a non-U.S. bank account for payment
- The agent's contract is governed by foreign law
Correct answer: The agent operates in a high-corruption-index country and interacts with foreign government officials
A foreign agent who interacts with government officials in a high-corruption environment is a classic FCPA risk scenario requiring enhanced due diligence.
Question 4: What is the purpose of including compliance representations and warranties in third-party contracts?
- To transfer all liability from the company to the vendor in the event of a violation
- To contractually require the third party to comply with applicable laws and the company's compliance standards (Correct answer)
- To replace the need for ongoing monitoring of the third party
- To allow the company to audit the vendor's personal finances
Correct answer: To contractually require the third party to comply with applicable laws and the company's compliance standards
Compliance representations and warranties contractually bind the third party to legal and ethical standards and provide grounds for termination or indemnification if violated.
Question 5: How should a compliance program handle a situation where a preferred vendor fails background screening?
- Override the screening result if the vendor has a strong track record with the company
- Conduct enhanced due diligence, document findings, and escalate to senior management before proceeding (Correct answer)
- Automatically blacklist the vendor without further review
- Defer to the business unit's preference and proceed with the contract
Correct answer: Conduct enhanced due diligence, document findings, and escalate to senior management before proceeding
A failed screening triggers enhanced review and escalation — not automatic blacklisting or override — ensuring informed risk decisions are made at the appropriate level.
Question 6: Which U.S. law most directly governs corporate liability for bribes paid by agents or intermediaries to foreign government officials?
- Sarbanes-Oxley Act (SOX)
- Foreign Corrupt Practices Act (FCPA) (Correct answer)
- Dodd-Frank Wall Street Reform Act
- Sherman Antitrust Act
Correct answer: Foreign Corrupt Practices Act (FCPA)
The FCPA prohibits U.S. companies and persons from bribing foreign government officials, including acts carried out through third-party agents.
Why is third-party due diligence considered a critical component of a CCCP-level compliance program?