Third-Party and Vendor Compliance Flashcards
7 cards from real CCO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Third-Party and Vendor Compliance flashcards as text
What does 'inherent risk' mean in the context of third-party vendor risk assessment?
Answer: The level of risk present before any mitigating controls are considered
Inherent risk is the gross or unmitigated risk that a vendor relationship poses before any controls, contractual protections, or monitoring activities are applied.
Under the OCC's guidance on third-party risk management, which of the following is considered a 'critical activity' requiring heightened oversight?
Answer: Outsourcing core banking processes or functions that could harm customers if disrupted
The OCC defines critical activities as those that could cause significant customer harm, reputational damage, or safety and soundness concerns if the third party fails to perform, requiring enhanced due diligence.
A company's vendor code of conduct should primarily do which of the following?
Answer: Communicate the organization's compliance expectations to all vendors and require written acknowledgment
A vendor code of conduct formally communicates the compliance, ethical, and legal standards the organization expects from its vendors and typically requires vendors to sign an acknowledgment of these requirements.
What is 'vendor concentration risk' in a third-party compliance program?
Answer: The risk arising when too many critical functions depend on a single vendor, creating a single point of failure
Vendor concentration risk occurs when an organization relies too heavily on a single third party for critical functions, so any disruption to that vendor can cripple the organization's operations and compliance posture.
Which of the following is a key indicator that a third-party vendor's compliance program is inadequate?
Answer: The vendor is unable to provide documentation of its compliance policies, training records, or audit results
An inability to produce compliance documentation is a red flag that the vendor's program exists only on paper or not at all, signaling significant risk to the contracting organization.
In the context of anti-bribery compliance, what is a 'red flag' that should heighten scrutiny of a third-party intermediary?
Answer: The intermediary requests unusual payment structures such as cash payments or payments to a third country
Unusual payment requests—such as cash, payments to undisclosed parties, or payments routed through unrelated jurisdictions—are classic red flags for potential bribery or money laundering through third parties.
What is the purpose of a 'right to audit' clause in a vendor contract?
Answer: To give the organization the contractual right to review and inspect the vendor's compliance-related records and processes
A right-to-audit clause preserves the organization's ability to independently verify that the vendor is complying with contractual, regulatory, and ethical obligations throughout the relationship.