← All CCEP Flashcard Decks

Third-Party Risk Management Flashcards

7 cards from real CCEP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Third-Party Risk Management flashcards as text
  1. What is a fundamental component of an effective third-party risk management (TPRM) program?

    Answer: Conducting thorough due diligence before engaging third parties

    Conducting thorough pre-engagement due diligence is a foundational element of TPRM, enabling organizations to assess and mitigate risks before entering into business relationships.

  2. Under the Foreign Corrupt Practices Act (FCPA), which party can be held liable for bribes paid by a third-party agent to a foreign official?

    Answer: The U.S. company that retained the agent, if it knew or had reason to know

    Under the FCPA, a U.S. company can be held liable for bribes paid by third-party agents if the company knew or consciously disregarded that the bribe would occur.

  3. Which of the following is considered a 'red flag' during third-party due diligence?

    Answer: The vendor requests unusually large upfront payments with no clear business justification

    Unusually large upfront payments with no clear business rationale are a classic red flag suggesting potential bribery or corruption risk in third-party relationships.

  4. What is the primary purpose of ongoing monitoring of third-party relationships?

    Answer: To ensure third parties continue to meet compliance standards throughout the relationship

    Ongoing monitoring ensures third parties maintain compliance standards throughout the relationship, since risks can change significantly after the initial onboarding period.

  5. What should compliance clauses in third-party contracts typically require?

    Answer: That the third party comply with applicable laws and the company's code of conduct

    Compliance clauses should contractually obligate third parties to comply with applicable laws and the company's code of conduct, establishing clear and enforceable compliance requirements.

  6. Which factor is most important when risk-tiering third-party relationships for due diligence purposes?

    Answer: The level of access the vendor has to sensitive data, company funds, or government officials

    Risk-tiering is primarily driven by the nature and extent of a third party's access to sensitive data, company funds, or government officials, as these factors create the most significant compliance exposure.

  7. Which document is most commonly used during third-party onboarding to gather structured information about a vendor's compliance practices and risk profile?

    Answer: A due diligence questionnaire

    A due diligence questionnaire is the standard tool used to systematically collect information about a third party's compliance program, ownership, financials, and potential risk factors.