CCM Third-Party and Vendor Compliance Management 5 — Questions and Answers
Question 1: What is the key difference between vendor offboarding and contract termination from a compliance perspective?
- They are interchangeable terms with no meaningful distinction
- Offboarding includes data return/destruction and access revocation, while termination is only the legal end of the contract (Correct answer)
- Contract termination automatically ensures all compliance obligations are satisfied
- Offboarding applies only to IT vendors, not service providers
Correct answer: Offboarding includes data return/destruction and access revocation, while termination is only the legal end of the contract
Offboarding encompasses the operational steps—such as data return, destruction, and system access removal—that must occur alongside or after legal termination.
Question 2: A compliance program requires vendors to complete annual self-attestation questionnaires. What is the main limitation of relying solely on this approach?
- Self-attestations are illegal under most US regulations
- Vendors may provide inaccurate or optimistic responses without independent verification (Correct answer)
- Annual frequency is too burdensome for vendors
- Self-attestations cannot be stored in vendor management systems
Correct answer: Vendors may provide inaccurate or optimistic responses without independent verification
Self-attestations depend on vendor honesty and competence; without independent verification, compliance gaps may go undetected.
Question 3: When assessing a vendor that processes protected health information (PHI), which US regulation primarily governs the required contractual safeguards?
- Gramm-Leach-Bliley Act (GLBA)
- Health Insurance Portability and Accountability Act (HIPAA) Business Associate Agreement requirements (Correct answer)
- Sarbanes-Oxley Act (SOX) Section 404
- Federal Trade Commission Act Section 5
Correct answer: Health Insurance Portability and Accountability Act (HIPAA) Business Associate Agreement requirements
HIPAA requires covered entities to execute Business Associate Agreements (BAAs) with vendors that access, use, or disclose PHI on their behalf.
Question 4: Which scenario represents an example of 'concentration risk' in third-party management?
- Using different vendors for each business function
- Relying on a single vendor for multiple critical services across the organization (Correct answer)
- Requiring vendors to obtain multiple certifications
- Distributing vendor management responsibilities across business units
Correct answer: Relying on a single vendor for multiple critical services across the organization
Concentration risk arises when an organization is overly dependent on one vendor, making any disruption to that vendor disproportionately impactful.
Question 5: What role does a vendor compliance scorecard serve in an ongoing monitoring program?
- It replaces the need for formal contracts with high-performing vendors
- It provides a structured, consistent way to track and compare vendor performance against compliance criteria over time (Correct answer)
- It is used exclusively for regulatory reporting to federal agencies
- It eliminates the need for periodic audits or site visits
Correct answer: It provides a structured, consistent way to track and compare vendor performance against compliance criteria over time
A vendor compliance scorecard enables objective, repeatable measurement of vendor performance, supporting trend analysis and informed risk decisions.
Question 6: A vendor operating in a foreign jurisdiction has different data privacy standards than those required by US law. What is the compliance manager's best course of action?
- Accept the foreign standard as equivalent and proceed
- Require the vendor to contractually commit to meeting US regulatory requirements regardless of local law (Correct answer)
- Exclude the vendor from all data-handling activities and find a domestic replacement immediately
- Report the discrepancy to the vendor's home country regulator
Correct answer: Require the vendor to contractually commit to meeting US regulatory requirements regardless of local law
Contracts should explicitly require vendors to meet the organization's applicable regulatory standards, even when operating under less stringent local laws.
Question 7: Which of the following is a leading practice when conducting due diligence on a prospective vendor that will access sensitive financial data?
- Reviewing only the vendor's marketing materials and client references
- Assessing the vendor's financial stability, security posture, regulatory history, and control environment before contract execution (Correct answer)
- Deferring all due diligence until after the vendor has been onboarded for 90 days
- Relying exclusively on the vendor's self-reported compliance certifications
Correct answer: Assessing the vendor's financial stability, security posture, regulatory history, and control environment before contract execution
Comprehensive pre-contract due diligence covering financial health, security, regulatory standing, and controls is essential before engaging a vendor with access to sensitive data.
What is the key difference between vendor offboarding and contract termination from a compliance perspective?