CCM Third-Party and Vendor Compliance Management 2 — Questions and Answers
Question 1: What is 'vendor tiering' in the context of third-party risk management?
- Ranking vendors by the length of their contracts
- Categorizing vendors by their geographic location
- Classifying vendors into risk levels to allocate due diligence and monitoring resources proportionally (Correct answer)
- Sorting vendors alphabetically for administrative ease
Correct answer: Classifying vendors into risk levels to allocate due diligence and monitoring resources proportionally
Vendor tiering assigns risk levels (e.g., critical, high, medium, low) based on factors such as data access, regulatory impact, and financial exposure, enabling the organization to focus compliance resources where risk is greatest.
Question 2: Which of the following is a significant red flag during third-party due diligence that should trigger enhanced scrutiny?
- The vendor uses a well-known cloud service provider
- The vendor declines to disclose ownership structure or beneficial owners (Correct answer)
- The vendor has ISO 27001 certification
- The vendor has been in operation for more than ten years
Correct answer: The vendor declines to disclose ownership structure or beneficial owners
Refusal to disclose ownership or beneficial owners raises anti-money laundering, sanctions, and corruption concerns, and is a classic red flag requiring enhanced due diligence.
Question 3: What key element must be included in a vendor contract to support ongoing compliance oversight?
- A clause limiting vendor liability to zero
- Compliance obligations, reporting requirements, and rights to terminate for non-compliance (Correct answer)
- A guarantee that vendor pricing will never increase
- A clause waiving all regulatory requirements
Correct answer: Compliance obligations, reporting requirements, and rights to terminate for non-compliance
Effective vendor contracts must specify the compliance standards the vendor must meet, how they must report compliance issues, and the organization's right to terminate if those standards are not upheld.
Question 4: How frequently should a compliance manager reassess a high-risk critical vendor relationship?
- Only at contract renewal
- Every five years
- At least annually, and upon any material change (Correct answer)
- Only when a regulatory examination is scheduled
Correct answer: At least annually, and upon any material change
High-risk vendors require at least annual reassessment, plus reviews triggered by material events such as data breaches, ownership changes, or regulatory actions, to ensure ongoing compliance alignment.
Question 5: What is the primary purpose of a vendor code of conduct?
- To limit the vendor's ability to work with competitors
- To define ethical and legal behavior standards that vendors must follow to do business with the organization (Correct answer)
- To set pricing benchmarks for vendor services
- To provide vendors with the organization's trade secrets
Correct answer: To define ethical and legal behavior standards that vendors must follow to do business with the organization
A vendor code of conduct communicates the ethical, legal, and compliance standards the organization expects all vendors to uphold, extending the organization's compliance culture to its supply chain.
Question 6: What does 'concentration risk' mean in the context of third-party compliance management?
- The risk that a vendor concentrates too many employees in one location
- The risk of over-reliance on a single vendor or small group of vendors for critical functions (Correct answer)
- The risk that compliance staff are focused on too many projects simultaneously
- The risk that vendor contracts are concentrated in a single legal jurisdiction
Correct answer: The risk of over-reliance on a single vendor or small group of vendors for critical functions
Concentration risk occurs when an organization depends heavily on one or a few vendors for critical services, meaning a failure or non-compliance event at that vendor could have an outsized impact on the organization.
Question 7: Under the GDPR, when a company shares personal data with a third-party vendor that processes data on its behalf, the vendor is classified as:
- A data controller with independent obligations
- A data processor subject to binding contractual data protection requirements (Correct answer)
- A data subject with rights under the regulation
- A supervisory authority responsible for enforcement
Correct answer: A data processor subject to binding contractual data protection requirements
Under GDPR, a vendor processing personal data on behalf of another organization is a data processor, and the controller must establish a Data Processing Agreement (DPA) outlining the processor's obligations.
What is 'vendor tiering' in the context of third-party risk management?