CCB Third-Party & Vendor Risk Management 2 — Questions and Answers
Question 1: What is the significance of the 'inherent risk' assessment in third-party risk management before controls are applied?
- It measures the risk that remains after all mitigating controls are in place
- It establishes the baseline level of risk a vendor relationship poses before any controls or mitigations are considered (Correct answer)
- It quantifies the financial cost of the vendor relationship
- It assesses the risk that a vendor will raise their prices
Correct answer: It establishes the baseline level of risk a vendor relationship poses before any controls or mitigations are considered
Inherent risk represents the raw or baseline risk of a vendor relationship without accounting for controls, providing the starting point for determining how much mitigation is needed and what residual risk will remain.
Question 2: Which regulatory framework specifically addresses third-party risk management requirements for financial institutions?
- ISO 14001
- OSHA 1910.119
- OCC Bulletin 2013-29 (Third-Party Relationships) (Correct answer)
- GAAP ASC 606
Correct answer: OCC Bulletin 2013-29 (Third-Party Relationships)
OCC Bulletin 2013-29 provides comprehensive guidance for national banks and federal savings associations on managing risks associated with third-party relationships, covering due diligence, contract provisions, oversight, and termination.
Question 3: A vendor risk assessment questionnaire (VRAQ) is BEST used to:
- Replace the need for a formal contract with the vendor
- Gather standardized information about a vendor's security, compliance, and operational practices to support risk evaluation (Correct answer)
- Determine the vendor's profitability margins
- Confirm the vendor's physical office location
Correct answer: Gather standardized information about a vendor's security, compliance, and operational practices to support risk evaluation
A VRAQ systematically collects information about a vendor's policies, controls, certifications, and practices across risk domains, enabling the compliance team to evaluate risk before and during the vendor relationship.
Question 4: What does 'concentration risk' mean in the context of third-party risk management?
- The risk that a vendor will dilute their focus by serving too many customers
- The risk arising from over-reliance on a single vendor or a small number of vendors for critical functions, which could cause systemic failure if that vendor fails (Correct answer)
- The risk that vendor employees are too concentrated in one geographic area
- The risk that a vendor concentrates too much sensitive data
Correct answer: The risk arising from over-reliance on a single vendor or a small number of vendors for critical functions, which could cause systemic failure if that vendor fails
Concentration risk occurs when an organization depends too heavily on one or a few vendors for critical operations, meaning a vendor failure, outage, or exit would disproportionately disrupt the organization's business.
Question 5: When should a vendor risk assessment be formally updated or repeated?
- Only at initial onboarding and never again
- Only when the vendor requests a review
- At contract renewal, when material changes occur in the vendor's business or the relationship, and on a periodic schedule based on risk tier (Correct answer)
- Every 10 years regardless of circumstances
Correct answer: At contract renewal, when material changes occur in the vendor's business or the relationship, and on a periodic schedule based on risk tier
Best practice requires reassessing vendor risk on a periodic schedule (more frequently for higher-risk vendors) and also upon triggering events such as contract renewal, significant changes in the vendor's ownership, financial health, or services provided.
Question 6: Which of the following is an example of a 'right-to-audit' clause in a vendor contract?
- A clause that allows the vendor to audit the organization's financials
- A clause granting the organization the right to conduct on-site inspections or review vendor records to verify compliance with contractual and regulatory requirements (Correct answer)
- A clause requiring the vendor to hire a specific accounting firm
- A clause limiting the number of invoices the vendor can submit
Correct answer: A clause granting the organization the right to conduct on-site inspections or review vendor records to verify compliance with contractual and regulatory requirements
A right-to-audit clause gives the organization (or its designated representative) contractual authority to examine the vendor's operations, records, and systems to verify that the vendor is meeting its contractual and compliance obligations.
Question 7: In the context of GDPR and third-party risk, what is a 'Data Processing Agreement' (DPA)?
- An agreement requiring the vendor to delete all data after each transaction
- A legally required contract between a data controller and a data processor that specifies the terms under which personal data may be processed on behalf of the controller (Correct answer)
- A financial agreement governing data storage costs
- An internal policy governing how employees handle data
Correct answer: A legally required contract between a data controller and a data processor that specifies the terms under which personal data may be processed on behalf of the controller
Under GDPR Article 28, when a controller engages a processor to handle personal data, a DPA is legally mandated to define the scope, nature, purpose, type of data, and the obligations and rights of both parties.
What is the significance of the 'inherent risk' assessment in third-party risk management before controls are applied?