Third-Party Risk Management Flashcards
7 cards from real CCEP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Third-Party Risk Management flashcards as text
What is a fundamental component of an effective third-party risk management (TPRM) program?
Answer: Conducting thorough due diligence before engaging third parties
Conducting thorough pre-engagement due diligence is a foundational element of TPRM, enabling organizations to assess and mitigate risks before entering into business relationships.
Under the Foreign Corrupt Practices Act (FCPA), which party can be held liable for bribes paid by a third-party agent to a foreign official?
Answer: The U.S. company that retained the agent, if it knew or had reason to know
Under the FCPA, a U.S. company can be held liable for bribes paid by third-party agents if the company knew or consciously disregarded that the bribe would occur.
Which of the following is considered a 'red flag' during third-party due diligence?
Answer: The vendor requests unusually large upfront payments with no clear business justification
Unusually large upfront payments with no clear business rationale are a classic red flag suggesting potential bribery or corruption risk in third-party relationships.
What is the primary purpose of ongoing monitoring of third-party relationships?
Answer: To ensure third parties continue to meet compliance standards throughout the relationship
Ongoing monitoring ensures third parties maintain compliance standards throughout the relationship, since risks can change significantly after the initial onboarding period.
What should compliance clauses in third-party contracts typically require?
Answer: That the third party comply with applicable laws and the company's code of conduct
Compliance clauses should contractually obligate third parties to comply with applicable laws and the company's code of conduct, establishing clear and enforceable compliance requirements.
Which factor is most important when risk-tiering third-party relationships for due diligence purposes?
Answer: The level of access the vendor has to sensitive data, company funds, or government officials
Risk-tiering is primarily driven by the nature and extent of a third party's access to sensitive data, company funds, or government officials, as these factors create the most significant compliance exposure.
Which document is most commonly used during third-party onboarding to gather structured information about a vendor's compliance practices and risk profile?
Answer: A due diligence questionnaire
A due diligence questionnaire is the standard tool used to systematically collect information about a third party's compliance program, ownership, financials, and potential risk factors.