โ† All CCO Flashcard Decks

Third-Party and Vendor Compliance Flashcards

7 cards from real CCO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Third-Party and Vendor Compliance flashcards as text
  1. Which phase of the third-party lifecycle is most critical for identifying compliance risks before a vendor relationship begins?

    Answer: Due diligence and onboarding

    Due diligence during onboarding is the most critical phase because it identifies compliance, legal, and reputational risks before the organization is exposed through the relationship.

  2. A CCO discovers that a third-party vendor has been convicted of bribery in a foreign jurisdiction. Under the Foreign Corrupt Practices Act (FCPA), what is the primary concern for the organization?

    Answer: The organization may be held liable for the vendor's corrupt acts performed on its behalf

    The FCPA extends liability to companies for corrupt acts committed by third parties acting on their behalf, making thorough vendor vetting essential.

  3. What is the primary purpose of a vendor risk tiering system in a compliance program?

    Answer: To allocate oversight resources proportionally based on the risk each vendor poses

    Risk tiering allows a compliance program to focus its limited oversight resources on vendors that pose the greatest potential harm, making the program more efficient and effective.

  4. Which element is typically included in a vendor contract's compliance addendum?

    Answer: Audit rights allowing the organization to inspect the vendor's compliance records

    Audit rights in compliance addenda give organizations the ability to verify that vendors are meeting their contractual and regulatory obligations.

  5. When a vendor operates as a 'fourth party' (a subcontractor to your direct vendor), what is the organization's best practice?

    Answer: Require direct vendors to flow down compliance obligations and monitor their subcontractors

    Organizations manage fourth-party risk by requiring direct vendors to impose equivalent compliance requirements on their subcontractors and to monitor compliance accordingly.

  6. A CCO learns that a key supplier is experiencing severe financial distress. From a compliance perspective, what is the primary risk?

    Answer: The supplier may cut corners on compliance controls, increasing regulatory and reputational risk

    Financially distressed vendors often reduce compliance spending as a cost-cutting measure, which can lead to regulatory violations, data breaches, or other compliance failures that expose the contracting organization.

  7. Which regulatory framework specifically requires financial institutions to conduct due diligence on third-party vendors who handle sensitive customer data?

    Answer: Gramm-Leach-Bliley Act (GLBA)

    The GLBA requires financial institutions to have programs ensuring customer financial information remains protected even when shared with or processed by third-party service providers.