CORES Vendor & Third-Party Risk Oversight 2 — Questions and Answers
Question 1: A bank discovers that a critical payment processor subcontracted data handling to a fourth-party provider without prior notification. What is the MOST appropriate immediate response?
- Terminate the primary vendor contract immediately
- Invoke the contract clause requiring prior approval for subcontracting and conduct a risk assessment of the fourth party (Correct answer)
- Report the incident to regulators before investigating further
- Accept the arrangement if the fourth party has an ISO 27001 certification
Correct answer: Invoke the contract clause requiring prior approval for subcontracting and conduct a risk assessment of the fourth party
Contract clauses requiring notification and approval for subcontracting are the mechanism to enforce fourth-party visibility; invoking them and assessing the risk is the appropriate first step.
Question 2: Which metric is MOST useful for measuring the effectiveness of a vendor risk management program over time?
- Total number of vendors onboarded per quarter
- Percentage of vendors with completed and current risk assessments (Correct answer)
- Average contract value across the vendor portfolio
- Number of vendor relationship managers assigned
Correct answer: Percentage of vendors with completed and current risk assessments
Tracking the percentage of vendors with current risk assessments directly reflects program coverage and discipline.
Question 3: A vendor's SOC 2 Type II report reveals several exceptions in access control user provisioning. What does this finding most directly indicate?
- The vendor's financial stability is at risk
- Controls related to logical access may not be operating effectively throughout the audit period (Correct answer)
- The vendor's disaster recovery plan is inadequate
- The audit firm failed to conduct a sufficient review
Correct answer: Controls related to logical access may not be operating effectively throughout the audit period
SOC 2 Type II exceptions indicate that a stated control did not operate as designed during the period covered by the report.
Question 4: Under the OCC's third-party risk management guidance, which vendors typically require the MOST rigorous due diligence?
- Vendors providing generic office supplies
- Vendors involved in critical activities or handling sensitive customer data (Correct answer)
- Vendors with the lowest contract values
- Vendors whose services are easily replaceable in the market
Correct answer: Vendors involved in critical activities or handling sensitive customer data
OCC guidance directs heightened scrutiny toward vendors supporting critical activities or accessing sensitive data due to the elevated risk they pose.
Question 5: What is 'concentration risk' in the context of third-party vendor management?
- The risk that a vendor focuses too narrowly on a single product line
- The risk arising from over-reliance on a single vendor or a small group of vendors for critical services (Correct answer)
- The risk that vendor contracts are concentrated in one legal jurisdiction
- The risk that vendor assessments are performed by only one internal team
Correct answer: The risk arising from over-reliance on a single vendor or a small group of vendors for critical services
Concentration risk occurs when an organization depends heavily on one or few vendors, creating systemic vulnerability if that vendor fails.
Question 6: Which of the following is a key component of a robust vendor exit strategy?
- Ensuring the vendor receives a positive performance review before offboarding
- Defining data retrieval, transition timelines, and alternative sourcing plans before contract termination (Correct answer)
- Allowing the vendor to self-certify that all data has been returned or destroyed
- Waiting until contract expiration to begin planning for service continuity
Correct answer: Defining data retrieval, transition timelines, and alternative sourcing plans before contract termination
A robust exit strategy must be planned proactively, covering data handling, service transition, and backup sourcing to prevent disruption.
Question 7: A financial institution uses a cloud provider for core banking infrastructure. Which third-party risk concern is MOST unique to cloud service arrangements compared to traditional outsourcing?
- Vendor financial stability
- Multi-tenancy and shared infrastructure creating data segregation challenges (Correct answer)
- The need for a service level agreement
- Requirement to perform periodic vendor audits
Correct answer: Multi-tenancy and shared infrastructure creating data segregation challenges
Cloud multi-tenancy means multiple clients share underlying infrastructure, raising unique concerns about data isolation that traditional dedicated outsourcing does not present.
A bank discovers that a critical payment processor subcontracted data handling to a fourth-party provider without prior notification.
What is the MOST appropriate immediate response?