CCM Third-Party and Vendor Compliance Management 4 — Questions and Answers
Question 1: A vendor experiences a data breach affecting your organization's customer records. Under a robust third-party contract, what obligation should the vendor have?
- Notify the organization within a contractually defined timeframe (Correct answer)
- Quietly remediate the breach without disclosure to avoid reputational damage
- Transfer liability to the organization's cyber insurance policy
- Immediately terminate the contract and destroy all data
Correct answer: Notify the organization within a contractually defined timeframe
Contracts should require vendors to notify the organization promptly after a breach so the organization can fulfill its own regulatory notification obligations.
Question 2: Which metric is most useful for measuring the effectiveness of a third-party compliance monitoring program?
- Number of vendor contracts signed per quarter
- Percentage of vendors with no overdue remediation items (Correct answer)
- Total spend managed through approved vendors
- Average contract negotiation cycle time
Correct answer: Percentage of vendors with no overdue remediation items
Tracking the percentage of vendors with no overdue remediation items directly measures how well compliance gaps are being resolved.
Question 3: What is the primary purpose of including a 'right-to-audit' clause in a vendor agreement?
- To allow the organization to renegotiate pricing annually
- To give the organization the ability to verify vendor compliance with contractual obligations (Correct answer)
- To require vendors to share their internal financial statements
- To enable immediate contract termination without cause
Correct answer: To give the organization the ability to verify vendor compliance with contractual obligations
A right-to-audit clause ensures the organization can independently verify that vendors are meeting their compliance and contractual commitments.
Question 4: A compliance manager discovers that a critical vendor is subcontracting work to an unapproved fourth party. What is the most appropriate immediate action?
- Terminate the vendor contract immediately
- Notify internal legal and risk teams and require the vendor to cease unapproved subcontracting (Correct answer)
- Accept the arrangement if the fourth party has relevant certifications
- Document the finding and address it at the next annual review
Correct answer: Notify internal legal and risk teams and require the vendor to cease unapproved subcontracting
Unapproved subcontracting is a contract breach requiring immediate escalation to legal and risk, and remediation by the vendor.
Question 5: Under the US FFIEC guidance for financial institutions, how should third-party risk management be integrated into enterprise risk management?
- As a standalone program with no connection to enterprise risk
- As a component embedded within the institution's overall risk governance framework (Correct answer)
- Only addressed after a regulatory exam finding
- Delegated entirely to the procurement department
Correct answer: As a component embedded within the institution's overall risk governance framework
FFIEC guidance requires financial institutions to incorporate third-party risk management into their broader enterprise risk governance structures.
Question 6: Which of the following best describes 'inherent risk' in the context of vendor risk assessment?
- Risk remaining after the vendor's controls are applied
- Risk that exists before any controls or mitigations are considered (Correct answer)
- Risk transferred to the vendor through the contract
- Risk identified during a post-incident review
Correct answer: Risk that exists before any controls or mitigations are considered
Inherent risk is the level of risk posed by a vendor relationship before accounting for any controls or mitigating factors.
Question 7: A vendor's SOC 2 Type II report contains several exceptions noted by the auditor. How should a compliance manager interpret this?
- The vendor fails all compliance requirements and must be immediately offboarded
- The exceptions indicate control deficiencies that require further evaluation and possible compensating controls (Correct answer)
- Exceptions in SOC 2 reports are standard and require no further review
- The report should be accepted without review as a third-party validation
Correct answer: The exceptions indicate control deficiencies that require further evaluation and possible compensating controls
Auditor exceptions in a SOC 2 Type II report signal areas where controls may not be operating effectively, warranting deeper analysis and risk mitigation.
A vendor experiences a data breach affecting your organization's customer records.
Under a robust third-party contract, what obligation should the vendor have?