CGRC Third-Party Risk 2 — Questions and Answers
Question 1: Which document formally establishes the security and compliance obligations a vendor must meet before onboarding?
- Master Service Agreement (MSA)
- Third-Party Security Questionnaire (Correct answer)
- Vendor Risk Assessment Report
- Data Processing Agreement (DPA)
Correct answer: Third-Party Security Questionnaire
A Third-Party Security Questionnaire collects information about a vendor's security controls and compliance posture prior to onboarding.
Question 2: A vendor stores customer PII on behalf of your organization. Under GDPR, what role does this vendor hold?
- Data Controller
- Data Processor (Correct answer)
- Data Custodian
- Data Steward
Correct answer: Data Processor
Under GDPR, a party that processes personal data on behalf of another is classified as a Data Processor.
Question 3: What is the primary goal of a fourth-party risk assessment?
- Evaluating your organization's internal audit function
- Assessing risks introduced by your vendors' own suppliers (Correct answer)
- Reviewing contract terms negotiated by third parties
- Measuring residual risk after vendor controls are applied
Correct answer: Assessing risks introduced by your vendors' own suppliers
Fourth-party risk assessment focuses on the subcontractors and suppliers used by your direct vendors, extending the risk visibility beyond the immediate third party.
Question 4: Which activity is most important when a high-risk vendor relationship is terminated?
- Issuing a final invoice reconciliation
- Ensuring data is returned or securely destroyed per contract terms (Correct answer)
- Updating the vendor's risk tier classification in the registry
- Sending a formal termination notice to regulators
Correct answer: Ensuring data is returned or securely destroyed per contract terms
Offboarding a high-risk vendor must include verified data return or destruction to prevent unauthorized retention of sensitive information.
Question 5: A TPRM program assigns vendors to risk tiers. Which factor most directly determines a vendor's initial risk tier?
- Vendor's annual revenue
- Vendor's geographic location
- Criticality of services provided and data access level (Correct answer)
- Length of the existing vendor relationship
Correct answer: Criticality of services provided and data access level
Risk tiering is primarily driven by the sensitivity of data accessed and the criticality of services the vendor delivers to operations.
Question 6: Which clause in a vendor contract provides your organization the right to review the vendor's security controls and audit logs?
- Indemnification clause
- Right-to-audit clause (Correct answer)
- Force majeure clause
- Limitation of liability clause
Correct answer: Right-to-audit clause
A right-to-audit clause grants the organization the contractual authority to conduct or commission audits of the vendor's security practices.
Question 7: An organization discovers a critical vulnerability in a third-party software library embedded in its product. What is the FIRST step under a vendor risk management response?
- Immediately terminate the vendor contract
- Notify the vendor and request a remediation timeline (Correct answer)
- Publish a public advisory about the vulnerability
- Rebuild the software without the third-party library
Correct answer: Notify the vendor and request a remediation timeline
The first step is to notify the vendor and obtain a remediation timeline so coordinated patching can occur before broader disclosure.
Which document formally establishes the security and compliance obligations a vendor must meet before onboarding?