Third-Party Risk Management Flashcards
7 cards from real CCEP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Third-Party Risk Management flashcards as text
What is the recommended first step when onboarding a new third-party vendor?
Answer: Conducting a risk assessment to determine the appropriate level of due diligence
A risk assessment should be conducted first so that the scope and depth of due diligence are proportional to the risks the third party actually presents.
Which type of third party typically requires the most rigorous due diligence under anti-corruption compliance frameworks?
Answer: Government-facing sales agents operating in high-risk countries
Government-facing sales agents in high-risk countries pose the greatest bribery and corruption risk, requiring the most intensive due diligence under laws like the FCPA and UK Bribery Act.
What is 'fourth-party risk' in the context of third-party risk management?
Answer: Risk arising from sub-vendors or service providers that your direct third parties engage
Fourth-party risk refers to risks arising from the sub-vendors or downstream service providers engaged by your direct third parties, creating extended supply chain exposure beyond your immediate vendor relationships.
How does the EU General Data Protection Regulation (GDPR) specifically affect third-party risk management?
Answer: It requires companies to execute Data Processing Agreements with third parties that handle personal data
GDPR requires companies to enter into Data Processing Agreements (DPAs) with third parties that process personal data, ensuring appropriate data protection obligations and accountability are contractually established.
What action should a compliance team take if a third party fails a compliance audit?
Answer: Assess the severity of findings, require remediation, and decide whether to continue the relationship
When a third party fails a compliance audit, the appropriate response is to assess severity, require corrective action where feasible, and make a risk-informed decision about whether to continue the relationship.
What is the primary purpose of obtaining a compliance certification from a third party?
Answer: To obtain a formal attestation that the third party meets required compliance and ethical standards
A compliance certification is a formal documented attestation from the third party confirming that it meets the company's required compliance standards and applicable legal obligations.
What is the significance of 'beneficial ownership' information in third-party due diligence?
Answer: It reveals the actual individuals who own or control the third party, which may uncover conflicts of interest or sanctions exposure
Identifying beneficial ownership reveals the real individuals who ultimately own or control a third party, which can uncover hidden conflicts of interest, sanctions risks, or corruption exposures not apparent from official corporate records alone.