CRA Third-Party and Vendor Risk Management 1 — Questions and Answers
Question 1: What is the primary purpose of a third-party risk management (TPRM) program?
- To identify, assess, and mitigate risks introduced by external vendors and service providers (Correct answer)
- To eliminate all vendor relationships that pose any potential risk
- To transfer all operational responsibilities to third-party providers
- To ensure all vendors use the same technology platforms
Correct answer: To identify, assess, and mitigate risks introduced by external vendors and service providers
TPRM programs are designed to systematically identify, assess, and manage risks that arise from relationships with external vendors and service providers.
Question 2: Which of the following best describes 'fourth-party risk' in vendor risk management?
- Risk from vendors who have not been directly contracted
- Risk posed by the subcontractors or suppliers used by your direct vendors (Correct answer)
- Risk arising from four separate vendor failure categories
- Risk from vendors operating across four different countries
Correct answer: Risk posed by the subcontractors or suppliers used by your direct vendors
Fourth-party risk refers to risks posed by the subcontractors or suppliers of your direct (third-party) vendors, extending risk visibility beyond direct relationships.
Question 3: What is vendor tiering classification primarily used for in a TPRM program?
- Ranking vendors by revenue generated for the organization
- Determining the appropriate level of due diligence and oversight based on risk exposure (Correct answer)
- Sorting vendors alphabetically for contract management purposes
- Classifying vendors by geographic headquarters location
Correct answer: Determining the appropriate level of due diligence and oversight based on risk exposure
Vendor tiering helps organizations apply proportionate due diligence and oversight, directing the most rigorous scrutiny toward vendors that present the greatest risk.
Question 4: What is the purpose of a right-to-audit clause in a vendor contract?
- To allow the vendor to audit the organization's financial records
- To permit the organization to inspect vendor operations and verify compliance with contractual obligations (Correct answer)
- To authorize independent third-party auditors to review both parties equally
- To enable regulatory bodies to directly examine vendor compliance on demand
Correct answer: To permit the organization to inspect vendor operations and verify compliance with contractual obligations
A right-to-audit clause grants the contracting organization authority to inspect and verify a vendor's controls, processes, and compliance with agreed-upon obligations.
Question 5: Which risk category is most directly associated with a critical vendor experiencing financial insolvency?
- Reputational risk from public disclosure
- Concentration risk from portfolio overexposure
- Vendor exit and service continuity risk (Correct answer)
- Compliance risk from regulatory reporting gaps
Correct answer: Vendor exit and service continuity risk
Vendor insolvency creates exit and continuity risk because it threatens the ongoing delivery of critical services or products that the organization depends on.
Question 6: What is a key indicator that an organization may have excessive concentration risk in its vendor portfolio?
- Engaging more than ten vendors within a single service category
- Over-reliance on a single vendor for the delivery of critical business services (Correct answer)
- Using vendors headquartered in more than three geographic regions
- Contracting with vendors who also serve direct competitors
Correct answer: Over-reliance on a single vendor for the delivery of critical business services
Concentration risk arises when excessive dependency is placed on a single vendor, creating significant vulnerability if that vendor fails, underperforms, or exits the market.
Question 7: In TPRM, what does the term 'vendor lifecycle management' encompass?
- Managing only the contract negotiation and execution phases of vendor relationships
- Overseeing vendor relationships from initial due diligence through offboarding and termination (Correct answer)
- Tracking vendor product development cycles and release schedules
- Monitoring vendor financial performance from IPO through potential acquisition
Correct answer: Overseeing vendor relationships from initial due diligence through offboarding and termination
Vendor lifecycle management covers all stages of a vendor relationship, including selection, due diligence, onboarding, ongoing monitoring, and offboarding.
What is the primary purpose of a third-party risk management (TPRM) program?