CORES Vendor & Third-Party Risk Oversight 3 — Questions and Answers
Question 1: An organization's TPRM policy requires annual reassessment of all vendors. A critical vendor has undergone a significant merger mid-year. What action should the risk team take?
- Wait for the scheduled annual review since the policy does not allow exceptions
- Trigger an out-of-cycle risk reassessment due to the material change in the vendor's profile (Correct answer)
- Request only an updated vendor questionnaire without reassessing risk ratings
- Reduce oversight since larger merged entities are generally more stable
Correct answer: Trigger an out-of-cycle risk reassessment due to the material change in the vendor's profile
Material changes such as mergers represent trigger events that warrant immediate reassessment regardless of the regular review schedule.
Question 2: Which element is MOST critical when reviewing a vendor's business continuity plan (BCP) during due diligence?
- The aesthetic quality of the BCP documentation
- Whether the BCP has been tested and includes recovery time objectives aligned with your own RTOs (Correct answer)
- The length of the BCP document
- Whether the vendor uses the same BCP software as your organization
Correct answer: Whether the BCP has been tested and includes recovery time objectives aligned with your own RTOs
A BCP is only credible if it has been tested and its recovery objectives are compatible with the client organization's own continuity requirements.
Question 3: What is the primary purpose of including a 'right to audit' clause in a vendor contract?
- To allow the organization to renegotiate pricing at any time
- To grant the organization the ability to independently verify vendor compliance and control effectiveness (Correct answer)
- To require the vendor to audit its own subcontractors annually
- To ensure the vendor pays for all compliance-related costs
Correct answer: To grant the organization the ability to independently verify vendor compliance and control effectiveness
Right-to-audit clauses preserve the client's ability to independently verify that the vendor is meeting contractual and regulatory obligations.
Question 4: A vendor that processes payroll for your organization suffers a ransomware attack. Under a sound third-party incident response protocol, what should your organization do FIRST?
- Immediately terminate the vendor relationship
- Activate your incident response plan, contact the vendor for status, and assess impact on your operations (Correct answer)
- Notify all employees that payroll may be delayed
- Wait 48 hours to see if the vendor resolves the issue independently
Correct answer: Activate your incident response plan, contact the vendor for status, and assess impact on your operations
Activating your own incident response plan and gathering vendor status information is the first step to assessing and managing the impact on your organization.
Question 5: Which risk tier classification approach is MOST consistent with regulatory expectations for prioritizing vendor oversight resources?
- Classifying all vendors as high risk to ensure maximum coverage
- Risk-based tiering that considers criticality of service, data sensitivity, and substitutability (Correct answer)
- Tiering vendors solely by contract dollar value
- Assigning tiers alphabetically by vendor name for administrative simplicity
Correct answer: Risk-based tiering that considers criticality of service, data sensitivity, and substitutability
Regulators expect a risk-based approach that allocates oversight intensity based on the actual risk profile of each vendor relationship.
Question 6: What is the primary risk of allowing vendor access credentials to remain active after a service engagement ends?
- It increases future vendor onboarding time
- It creates unauthorized access pathways that could lead to data breaches or system compromise (Correct answer)
- It may violate vendor contract terms
- It increases the organization's compliance documentation burden
Correct answer: It creates unauthorized access pathways that could lead to data breaches or system compromise
Orphaned credentials are a leading cause of unauthorized access, as former vendors or their compromised accounts can still reach sensitive systems.
Question 7: Which of the following BEST describes 'nth-party risk' in vendor management?
- Risk arising from the organization's own internal operational failures
- Risk from subcontractors, their subcontractors, and further layers of the vendor supply chain beyond the direct vendor (Correct answer)
- Risk associated with vendors in countries with less stable political environments
- Risk that emerges when a vendor serves more than 'n' clients simultaneously
Correct answer: Risk from subcontractors, their subcontractors, and further layers of the vendor supply chain beyond the direct vendor
Nth-party risk refers to the cascading risks that propagate through multiple layers of a vendor's own supply chain, beyond the organization's direct visibility.
An organization's TPRM policy requires annual reassessment of all vendors.
A critical vendor has undergone a significant merger mid-year.
What action should the risk team take?