Third-Party and Vendor Compliance Flashcards
7 cards from real CCO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Third-Party and Vendor Compliance flashcards as text
When offboarding a vendor who handled sensitive personal data, what is the compliance officer's primary obligation?
Answer: Verify that the vendor has returned or securely destroyed all personal data per contractual and regulatory requirements
Data destruction or return upon offboarding is a critical regulatory and contractual requirement under frameworks like GDPR and CCPA to prevent unauthorized retention or use of personal data by former vendors.
Which due diligence tool is most effective for screening third-party vendors against global sanctions lists and politically exposed persons (PEPs)?
Answer: An automated screening solution integrated with OFAC, UN, and other global watchlists
Automated screening tools that continuously check vendors against OFAC, EU, UN, and other sanctions and PEP lists provide the most reliable and scalable compliance coverage for anti-money laundering and sanctions obligations.
A vendor notifies your organization of a data breach affecting data it processes on your behalf. Under GDPR, who bears primary accountability to the affected data subjects?
Answer: The organization (data controller), which remains accountable to data subjects for how their data was processed
Under GDPR, the data controller retains accountability to data subjects regardless of delegation to a processor; the organization must notify supervisory authorities and affected individuals within required timeframes.
What does a vendor's SOC 2 Type II report assess?
Answer: The effectiveness of the vendor's controls related to security, availability, and confidentiality over a defined operating period
A SOC 2 Type II report evaluates whether a service organization's controls related to the Trust Service Criteria (security, availability, processing integrity, confidentiality, privacy) were operating effectively over a review period.
In third-party compliance management, what is the significance of 'residual risk'?
Answer: It is the risk that remains after all mitigating controls and contractual protections have been applied
Residual risk is what the organization accepts after controls are in place; if residual risk exceeds the organization's risk appetite, additional controls or relationship termination may be required.
Which best describes the 'flow-down' requirement in third-party compliance programs?
Answer: Requiring vendors to impose the same compliance standards on their subcontractors that the organization imposes on the vendors
Flow-down clauses extend the organization's compliance requirements through the supply chain, ensuring that fourth parties and beyond are also bound by the same ethical and regulatory standards.
What is the most effective way to ensure that a third-party compliance program remains current as vendor relationships and regulations evolve?
Answer: Implement periodic re-assessments, continuous monitoring, and annual program reviews tied to regulatory changes and vendor risk changes
Third-party compliance programs must be living documents that incorporate continuous monitoring, periodic re-assessments, and updates triggered by regulatory changes or material changes in vendor risk profiles.