CCO Third-Party and Vendor Compliance 2 — Questions and Answers
Question 1: What does 'inherent risk' mean in the context of third-party vendor risk assessment?
- The risk that remains after all controls are applied
- The level of risk present before any mitigating controls are considered (Correct answer)
- The risk transferred to the vendor through contract terms
- The financial risk of vendor non-performance
Correct answer: The level of risk present before any mitigating controls are considered
Inherent risk is the gross or unmitigated risk that a vendor relationship poses before any controls, contractual protections, or monitoring activities are applied.
Question 2: Under the OCC's guidance on third-party risk management, which of the following is considered a 'critical activity' requiring heightened oversight?
- Purchasing office supplies from an approved vendor
- Outsourcing core banking processes or functions that could harm customers if disrupted (Correct answer)
- Engaging a one-time consultant for a training seminar
- Using a standard cloud storage provider for non-sensitive files
Correct answer: Outsourcing core banking processes or functions that could harm customers if disrupted
The OCC defines critical activities as those that could cause significant customer harm, reputational damage, or safety and soundness concerns if the third party fails to perform, requiring enhanced due diligence.
Question 3: A company's vendor code of conduct should primarily do which of the following?
- Set pricing benchmarks for vendor negotiations
- Communicate the organization's compliance expectations to all vendors and require written acknowledgment (Correct answer)
- Replace the need for individual vendor contracts
- Guarantee vendor performance against SLAs
Correct answer: Communicate the organization's compliance expectations to all vendors and require written acknowledgment
A vendor code of conduct formally communicates the compliance, ethical, and legal standards the organization expects from its vendors and typically requires vendors to sign an acknowledgment of these requirements.
Question 4: What is 'vendor concentration risk' in a third-party compliance program?
- The risk that a vendor's workforce is too concentrated in one geographic area
- The risk arising when too many critical functions depend on a single vendor, creating a single point of failure (Correct answer)
- The risk that vendor pricing is concentrated among high-cost providers
- The risk that one vendor supplies competing firms
Correct answer: The risk arising when too many critical functions depend on a single vendor, creating a single point of failure
Vendor concentration risk occurs when an organization relies too heavily on a single third party for critical functions, so any disruption to that vendor can cripple the organization's operations and compliance posture.
Question 5: Which of the following is a key indicator that a third-party vendor's compliance program is inadequate?
- The vendor has fewer compliance staff than the hiring organization
- The vendor is unable to provide documentation of its compliance policies, training records, or audit results (Correct answer)
- The vendor's compliance program mirrors the organization's own program exactly
- The vendor's compliance officer has less tenure than the organization's CCO
Correct answer: The vendor is unable to provide documentation of its compliance policies, training records, or audit results
An inability to produce compliance documentation is a red flag that the vendor's program exists only on paper or not at all, signaling significant risk to the contracting organization.
Question 6: In the context of anti-bribery compliance, what is a 'red flag' that should heighten scrutiny of a third-party intermediary?
- The intermediary operates in multiple countries simultaneously
- The intermediary requests unusual payment structures such as cash payments or payments to a third country (Correct answer)
- The intermediary has staff who previously worked at a competitor
- The intermediary charges standard market rates for its services
Correct answer: The intermediary requests unusual payment structures such as cash payments or payments to a third country
Unusual payment requests—such as cash, payments to undisclosed parties, or payments routed through unrelated jurisdictions—are classic red flags for potential bribery or money laundering through third parties.
Question 7: What is the purpose of a 'right to audit' clause in a vendor contract?
- To allow the vendor to audit the organization's financial records
- To give the organization the contractual right to review and inspect the vendor's compliance-related records and processes (Correct answer)
- To permit the vendor to audit competitors on the organization's behalf
- To satisfy accounting standards for revenue recognition
Correct answer: To give the organization the contractual right to review and inspect the vendor's compliance-related records and processes
A right-to-audit clause preserves the organization's ability to independently verify that the vendor is complying with contractual, regulatory, and ethical obligations throughout the relationship.
What does 'inherent risk' mean in the context of third-party vendor risk assessment?