RCC RCC Third-Party and Vendor Compliance Management 2 — Questions and Answers
Question 1: Which regulatory guidance document addresses vendor management obligations for US financial institutions?
- OSHA 29 CFR 1910
- OCC Bulletin 2013-29 on Third-Party Relationships (Correct answer)
- EPA Clean Air Act regulations
- SEC Regulation FD
Correct answer: OCC Bulletin 2013-29 on Third-Party Relationships
OCC Bulletin 2013-29 provides comprehensive guidance for national banks and federal savings associations on managing risks associated with third-party relationships.
Question 2: When a critical vendor announces it is going out of business, the compliance officer's IMMEDIATE priority should be to:
- File a complaint with the vendor's regulator
- Activate the organization's vendor exit and contingency plan (Correct answer)
- Terminate all services immediately
- Wait for the vendor to provide further instructions
Correct answer: Activate the organization's vendor exit and contingency plan
A vendor exit plan ensures business continuity by documenting steps to migrate to an alternative provider while maintaining regulatory compliance obligations.
Question 3: What is the purpose of a vendor's SOC 2 Type II report in compliance due diligence?
- To confirm the vendor's financial solvency
- To provide evidence that the vendor's controls have been operating effectively over a defined period (Correct answer)
- To verify the vendor's marketing claims
- To assess the vendor's environmental compliance
Correct answer: To provide evidence that the vendor's controls have been operating effectively over a defined period
A SOC 2 Type II report, issued by an independent auditor, attests to the design and operating effectiveness of a service organization's controls over time.
Question 4: Which element of a vendor contract MOST directly supports compliance with data privacy regulations like CCPA or HIPAA?
- A payment terms clause
- Data processing agreements and data security requirements (Correct answer)
- A force majeure clause
- An exclusivity provision
Correct answer: Data processing agreements and data security requirements
Data processing agreements define how a vendor may collect, use, store, and protect personal data, which is a contractual requirement under many privacy regulations.
Question 5: An organization discovers that its marketing vendor is engaging in deceptive practices with consumers. Under FTC enforcement principles, the organization may face liability because:
- The FTC only pursues vendors, not their clients
- Companies are responsible for acts and practices performed by agents acting on their behalf (Correct answer)
- Marketing activities are exempt from FTC jurisdiction
- Vendor liability only applies to financial services firms
Correct answer: Companies are responsible for acts and practices performed by agents acting on their behalf
The FTC holds companies accountable for deceptive or unfair acts carried out by third parties acting on their behalf, including marketing vendors.
Question 6: What is a Vendor Risk Management (VRM) program PRIMARILY designed to do?
- Negotiate lower vendor prices
- Identify, assess, and mitigate risks posed by third-party relationships across their lifecycle (Correct answer)
- Automate vendor invoice processing
- Manage internal employee performance reviews
Correct answer: Identify, assess, and mitigate risks posed by third-party relationships across their lifecycle
A VRM program provides a structured framework for evaluating and managing the risks that third parties introduce throughout the entire vendor relationship lifecycle.
Which regulatory guidance document addresses vendor management obligations for US financial institutions?