Third-Party & Vendor Risk Management Flashcards
7 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Third-Party & Vendor Risk Management flashcards as text
What is the purpose of a vendor exit strategy or termination plan in third-party risk management?
Answer: To ensure the organization can transition services, retrieve data, and maintain business continuity if a vendor relationship is terminated, whether planned or abrupt
A vendor exit strategy ensures the organization can smoothly transition away from a vendor by addressing data retrieval, service continuity, knowledge transfer, and contract wind-down obligations, minimizing disruption regardless of the reason for termination.
Which metric is MOST useful for tracking the effectiveness of a third-party risk management program?
Answer: The percentage of vendors that have completed required risk assessments and remediated identified gaps within defined timeframes
Tracking the percentage of vendors that have completed risk assessments and closed identified gaps within required timeframes is a direct measure of the program's effectiveness in identifying and mitigating risk.
Which of the following best describes 'vendor offboarding' from a compliance perspective?
Answer: The structured process of terminating a vendor relationship that includes revoking access, retrieving or destroying data, ensuring contract obligations are met, and documenting the closure
Proper offboarding requires revoking all system access, ensuring data is returned or securely destroyed per contractual and regulatory requirements, confirming all obligations have been fulfilled, and documenting the process to demonstrate compliance.
Anti-bribery and corruption (ABC) due diligence on third parties is MOST important when:
Answer: The vendor acts as an agent, distributor, or intermediary that interacts with government officials on the organization's behalf
The FCPA and UK Bribery Act impose liability on organizations for corrupt acts committed by third-party agents and intermediaries acting on their behalf, making ABC due diligence especially critical for parties that interact with government officials.
What is the role of a 'vendor risk register' in third-party risk management?
Answer: A centralized record that documents all identified third-party risks, their severity, mitigation actions, owners, and status, serving as the master tracking tool for the TPRM program
A vendor risk register provides a consolidated, living document that captures all identified risks for each vendor relationship, tracks mitigation actions and their status, assigns ownership, and supports reporting and audits.
When a vendor undergoes a material change such as a merger, acquisition, or ownership change, the compliance team should FIRST:
Answer: Conduct a reassessment of the vendor's risk profile to determine whether the change affects the organization's risk exposure or contractual rights
A material change in a vendor's ownership or structure can alter its risk profile, data handling practices, or financial stability, triggering the need for an immediate reassessment and potentially invoking change-of-control provisions in the contract.
Which of the following best describes the 'residual risk' concept in third-party vendor risk management?
Answer: The risk that remains after all available controls, mitigations, and countermeasures have been applied to a third-party relationship
Residual risk is the level of risk that persists after all identified controls and mitigations have been implemented; if residual risk exceeds the organization's risk appetite, additional controls or risk acceptance decisions are required.