CCEP Third-Party Risk Management 1 — Questions and Answers
Question 1: What is a fundamental component of an effective third-party risk management (TPRM) program?
- Conducting thorough due diligence before engaging third parties (Correct answer)
- Limiting all business to direct employees only
- Delegating all compliance responsibilities to the third party
- Performing due diligence only after a compliance incident occurs
Correct answer: Conducting thorough due diligence before engaging third parties
Conducting thorough pre-engagement due diligence is a foundational element of TPRM, enabling organizations to assess and mitigate risks before entering into business relationships.
Question 2: Under the Foreign Corrupt Practices Act (FCPA), which party can be held liable for bribes paid by a third-party agent to a foreign official?
- Only the third-party agent who paid the bribe
- The U.S. company that retained the agent, if it knew or had reason to know (Correct answer)
- Only the foreign official who accepted the bribe
- The SEC, as the investigating and prosecuting body
Correct answer: The U.S. company that retained the agent, if it knew or had reason to know
Under the FCPA, a U.S. company can be held liable for bribes paid by third-party agents if the company knew or consciously disregarded that the bribe would occur.
Question 3: Which of the following is considered a 'red flag' during third-party due diligence?
- The vendor has a documented code of conduct and training program
- The vendor's fee structure is reasonable and consistent with market rates
- The vendor requests unusually large upfront payments with no clear business justification (Correct answer)
- The vendor provides verifiable references upon request
Correct answer: The vendor requests unusually large upfront payments with no clear business justification
Unusually large upfront payments with no clear business rationale are a classic red flag suggesting potential bribery or corruption risk in third-party relationships.
Question 4: What is the primary purpose of ongoing monitoring of third-party relationships?
- To renegotiate contract terms on an annual basis
- To ensure third parties continue to meet compliance standards throughout the relationship (Correct answer)
- To replace the need for due diligence at initial onboarding
- To reduce the overall number of approved vendors
Correct answer: To ensure third parties continue to meet compliance standards throughout the relationship
Ongoing monitoring ensures third parties maintain compliance standards throughout the relationship, since risks can change significantly after the initial onboarding period.
Question 5: What should compliance clauses in third-party contracts typically require?
- That the third party waive its right to request audits
- That the company assume all liability for third-party misconduct
- That the third party comply with applicable laws and the company's code of conduct (Correct answer)
- That the third party be granted access to all proprietary company information
Correct answer: That the third party comply with applicable laws and the company's code of conduct
Compliance clauses should contractually obligate third parties to comply with applicable laws and the company's code of conduct, establishing clear and enforceable compliance requirements.
Question 6: Which factor is most important when risk-tiering third-party relationships for due diligence purposes?
- The geographic location of the vendor's corporate headquarters
- The number of years the vendor has been in business
- The level of access the vendor has to sensitive data, company funds, or government officials (Correct answer)
- The total number of full-time employees the vendor has
Correct answer: The level of access the vendor has to sensitive data, company funds, or government officials
Risk-tiering is primarily driven by the nature and extent of a third party's access to sensitive data, company funds, or government officials, as these factors create the most significant compliance exposure.
Question 7: Which document is most commonly used during third-party onboarding to gather structured information about a vendor's compliance practices and risk profile?
- A standard purchase order
- A mutual nondisclosure agreement
- A due diligence questionnaire (Correct answer)
- A letter of intent to contract
Correct answer: A due diligence questionnaire
A due diligence questionnaire is the standard tool used to systematically collect information about a third party's compliance program, ownership, financials, and potential risk factors.
What is a fundamental component of an effective third-party risk management (TPRM) program?