CORES Vendor & Third-Party Risk Oversight 4 — Questions and Answers
Question 1: A vendor serving a community bank is acquired by a foreign company in a country with weak data privacy laws. What is the MOST significant risk this creates?
- Currency exchange rate risk affecting vendor pricing
- Data sovereignty and regulatory compliance risk due to potential foreign government access to customer data (Correct answer)
- Risk that the vendor will increase service quality after the acquisition
- Risk that the bank's internal IT team will need retraining
Correct answer: Data sovereignty and regulatory compliance risk due to potential foreign government access to customer data
Foreign acquisitions can expose customer data to the jurisdiction of countries with weaker privacy protections or government surveillance powers, creating regulatory and reputational risk.
Question 2: What distinguishes a 'critical vendor' from a 'non-critical vendor' in most TPRM frameworks?
- Critical vendors have longer contract terms
- Critical vendors provide services whose disruption would materially impact the organization's operations, revenue, or compliance posture (Correct answer)
- Critical vendors always have more employees than non-critical vendors
- Critical vendors are those that have never had a risk incident
Correct answer: Critical vendors provide services whose disruption would materially impact the organization's operations, revenue, or compliance posture
Criticality is defined by the impact of service disruption, not by vendor size, contract length, or historical performance.
Question 3: Which regulatory body issued the 'Guidance on Managing Outsourcing Risk' that directly governs how U.S. banks oversee third-party arrangements?
- Securities and Exchange Commission (SEC)
- Office of the Comptroller of the Currency (OCC) (Correct answer)
- Federal Trade Commission (FTC)
- Consumer Financial Protection Bureau (CFPB)
Correct answer: Office of the Comptroller of the Currency (OCC)
The OCC has issued specific guidance on third-party risk management that applies to national banks and federal savings associations.
Question 4: An organization's vendor risk committee is reviewing a high-risk vendor that has consistently failed to remediate identified control gaps. What is the MOST appropriate escalation action?
- Extend the remediation timeline indefinitely to avoid disruption
- Escalate to senior leadership and consider compensating controls, enhanced monitoring, or contract termination (Correct answer)
- Remove the vendor from the high-risk tier to reduce reporting burden
- Allow the vendor to self-assess the adequacy of their remediation efforts
Correct answer: Escalate to senior leadership and consider compensating controls, enhanced monitoring, or contract termination
Persistent control failures by a high-risk vendor require escalation to leadership and consideration of corrective actions up to and including termination.
Question 5: What is a key limitation of relying solely on vendor-provided self-assessment questionnaires (SAQs) for risk evaluation?
- SAQs take too long to complete for vendors
- SAQs depend entirely on vendor honesty and may not reflect actual control effectiveness (Correct answer)
- SAQs are not accepted by regulators as part of a TPRM program
- SAQs cover too many risk domains and create information overload
Correct answer: SAQs depend entirely on vendor honesty and may not reflect actual control effectiveness
Because SAQs are self-reported, they are subject to misrepresentation or misunderstanding, and must be supplemented with independent validation to be reliable.
Question 6: During vendor selection, a fintech startup offers cutting-edge services but has limited financial history. Which due diligence approach BEST addresses financial viability risk?
- Skip financial due diligence since startups are inherently innovative and low risk
- Review available financial statements, funding status, investor backing, and require escrow or performance bonds (Correct answer)
- Only assess the startup after one year of service delivery
- Accept the vendor's verbal assurance of financial stability
Correct answer: Review available financial statements, funding status, investor backing, and require escrow or performance bonds
For vendors with limited financial history, evaluating funding stability and requiring financial safeguards like escrow accounts compensates for the lack of track record.
Question 7: Which of the following is the BEST example of a compensating control when a vendor cannot meet a specific security requirement?
- Waiving the security requirement for that vendor entirely
- Implementing enhanced real-time monitoring of vendor activity and limiting their data access scope (Correct answer)
- Increasing the vendor's contract value to incentivize compliance
- Allowing a longer remediation window without additional safeguards
Correct answer: Implementing enhanced real-time monitoring of vendor activity and limiting their data access scope
Compensating controls substitute for missing primary controls by adding layers of detection and access restriction to reduce residual risk.
A vendor serving a community bank is acquired by a foreign company in a country with weak data privacy laws.
What is the MOST significant risk this creates?