โ† All CCB Flashcard Decks

Third-Party & Vendor Risk Management Flashcards

7 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Third-Party & Vendor Risk Management flashcards as text
  1. What is the significance of the 'inherent risk' assessment in third-party risk management before controls are applied?

    Answer: It establishes the baseline level of risk a vendor relationship poses before any controls or mitigations are considered

    Inherent risk represents the raw or baseline risk of a vendor relationship without accounting for controls, providing the starting point for determining how much mitigation is needed and what residual risk will remain.

  2. Which regulatory framework specifically addresses third-party risk management requirements for financial institutions?

    Answer: OCC Bulletin 2013-29 (Third-Party Relationships)

    OCC Bulletin 2013-29 provides comprehensive guidance for national banks and federal savings associations on managing risks associated with third-party relationships, covering due diligence, contract provisions, oversight, and termination.

  3. A vendor risk assessment questionnaire (VRAQ) is BEST used to:

    Answer: Gather standardized information about a vendor's security, compliance, and operational practices to support risk evaluation

    A VRAQ systematically collects information about a vendor's policies, controls, certifications, and practices across risk domains, enabling the compliance team to evaluate risk before and during the vendor relationship.

  4. What does 'concentration risk' mean in the context of third-party risk management?

    Answer: The risk arising from over-reliance on a single vendor or a small number of vendors for critical functions, which could cause systemic failure if that vendor fails

    Concentration risk occurs when an organization depends too heavily on one or a few vendors for critical operations, meaning a vendor failure, outage, or exit would disproportionately disrupt the organization's business.

  5. When should a vendor risk assessment be formally updated or repeated?

    Answer: At contract renewal, when material changes occur in the vendor's business or the relationship, and on a periodic schedule based on risk tier

    Best practice requires reassessing vendor risk on a periodic schedule (more frequently for higher-risk vendors) and also upon triggering events such as contract renewal, significant changes in the vendor's ownership, financial health, or services provided.

  6. Which of the following is an example of a 'right-to-audit' clause in a vendor contract?

    Answer: A clause granting the organization the right to conduct on-site inspections or review vendor records to verify compliance with contractual and regulatory requirements

    A right-to-audit clause gives the organization (or its designated representative) contractual authority to examine the vendor's operations, records, and systems to verify that the vendor is meeting its contractual and compliance obligations.

  7. In the context of GDPR and third-party risk, what is a 'Data Processing Agreement' (DPA)?

    Answer: A legally required contract between a data controller and a data processor that specifies the terms under which personal data may be processed on behalf of the controller

    Under GDPR Article 28, when a controller engages a processor to handle personal data, a DPA is legally mandated to define the scope, nature, purpose, type of data, and the obligations and rights of both parties.