← All CCEP Flashcard Decks

Third-Party Risk Management Flashcards

7 cards from real CCEP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Third-Party Risk Management flashcards as text
  1. What is the role of senior management and the board with respect to third-party risk management?

    Answer: To provide governance oversight, set tone from the top, and ensure adequate TPRM resources

    Senior management and the board are responsible for governance-level oversight—setting tone from the top, establishing TPRM policy, and ensuring the organization has adequate resources and structure to manage third-party risks.

  2. What is 'Know Your Vendor' (KYV) and why is it significant in compliance?

    Answer: A due diligence process for understanding a vendor's identity, ownership, and compliance risk profile

    KYV is a structured due diligence process that involves understanding a vendor's identity, beneficial ownership, business practices, and risk profile to proactively identify compliance risks before and during engagement.

  3. When a third party undergoes an acquisition and comes under new ownership, what should the compliance team do?

    Answer: Conduct a reassessment of the third party under its new ownership to identify any new or changed risks

    A change in ownership can materially alter a third party's risk profile, so reassessing the relationship under the new ownership structure is necessary to identify any new compliance risks or exposures.

  4. Which of the following best describes a risk-based approach to third-party management?

    Answer: Focusing more intensive due diligence and monitoring resources on higher-risk third parties

    A risk-based approach allocates compliance resources proportionally, directing more intensive scrutiny and ongoing monitoring toward third parties that present higher compliance risks.

  5. Under the UK Bribery Act, what is the 'adequate procedures' defense available to companies facing corporate liability for third-party bribery?

    Answer: Demonstrating the company had adequate anti-bribery procedures in place designed to prevent bribery

    The UK Bribery Act's 'adequate procedures' defense allows a company to avoid corporate liability if it can demonstrate it had proportionate, risk-based anti-bribery procedures in place to prevent associated persons from engaging in bribery.

  6. What is a key best practice for maintaining an effective enterprise-wide third-party compliance program?

    Answer: Maintaining a centralized registry of all third-party relationships with associated risk ratings and due diligence status

    A centralized third-party registry with associated risk ratings enables consistent oversight, efficient resource allocation, and provides auditable evidence of the organization's systematic approach to TPRM.

  7. Which of the following contractual provisions is most important for protecting a company's compliance interests in a third-party agreement?

    Answer: A right-to-audit clause allowing the company to inspect the third party's compliance records and practices

    A right-to-audit clause is a critical compliance protection because it allows the company to verify that the third party is adhering to contractual compliance obligations and applicable laws.