CCCP CCCP Third-Party & Vendor Compliance 2 — Questions and Answers
Question 1: What is 'ongoing monitoring' in a third-party compliance program, and why is it required?
- A one-time review conducted at contract signing
- Continuous or periodic reassessment of third-party risk throughout the relationship to detect emerging issues (Correct answer)
- An annual certification from the third party that they have no compliance violations
- Monitoring the vendor's social media accounts for negative press
Correct answer: Continuous or periodic reassessment of third-party risk throughout the relationship to detect emerging issues
Ongoing monitoring recognizes that third-party risk changes over time and that initial due diligence alone is insufficient to manage a dynamic risk relationship.
Question 2: Which of the following is a best practice for managing compliance risk within a company's supply chain?
- Limiting compliance requirements to Tier 1 direct suppliers only
- Extending compliance expectations, due diligence, and audit rights through multiple supply chain tiers based on risk (Correct answer)
- Relying solely on industry association certifications for supplier compliance
- Requiring all suppliers to be domiciled in the United States
Correct answer: Extending compliance expectations, due diligence, and audit rights through multiple supply chain tiers based on risk
Material compliance risks — such as forced labor, bribery, or sanctions violations — can originate in lower supply chain tiers, requiring risk-based oversight beyond Tier 1.
Question 3: What is the significance of 'right to audit' clauses in vendor contracts from a compliance perspective?
- They allow the company to unilaterally modify contract pricing
- They give the company the contractual right to examine the vendor's books and practices to verify compliance (Correct answer)
- They require the vendor to conduct self-audits and submit results quarterly
- They transfer financial liability to the vendor for any regulatory fines
Correct answer: They give the company the contractual right to examine the vendor's books and practices to verify compliance
Right-to-audit clauses enable the company to independently verify that third parties are actually complying with their contractual compliance obligations.
Question 4: How should a compliance officer respond when a business unit resists implementing third-party due diligence requirements, citing deal speed?
- Waive due diligence requirements for time-sensitive deals
- Explain the legal and reputational risks, offer streamlined processes for lower-risk situations, and escalate irreconcilable conflicts (Correct answer)
- Defer entirely to the business unit's commercial judgment
- Require all future vendor contracts to go through a six-month review process
Correct answer: Explain the legal and reputational risks, offer streamlined processes for lower-risk situations, and escalate irreconcilable conflicts
The compliance officer must educate on risk, offer practical efficiency solutions, and escalate when business pressure threatens to override necessary controls.
Question 5: Under the UK Bribery Act 2010, which defense is available to a commercial organization charged with failing to prevent bribery?
- The organization had no prior knowledge of the bribe
- The organization had 'adequate procedures' in place to prevent bribery (Correct answer)
- The bribe was paid by a third-party agent, not a direct employee
- The organization self-reported the violation within 30 days
Correct answer: The organization had 'adequate procedures' in place to prevent bribery
The UK Bribery Act's 'adequate procedures' defense requires that an organization implement proportionate anti-bribery procedures, including third-party controls.
Question 6: What is a 'sanctions screening' obligation in the context of third-party compliance?
- Reviewing vendor environmental sustainability certifications
- Checking third parties against OFAC and other sanctions lists to ensure the company does not transact with prohibited persons or entities (Correct answer)
- Verifying that vendors carry adequate liability insurance
- Screening vendors for negative news in trade publications
Correct answer: Checking third parties against OFAC and other sanctions lists to ensure the company does not transact with prohibited persons or entities
OFAC and other U.S. sanctions programs prohibit transactions with designated persons and entities, making pre-contract and ongoing sanctions screening a legal compliance requirement.
What is 'ongoing monitoring' in a third-party compliance program, and why is it required?