CORES Vendor & Third-Party Risk Oversight 5 — Questions and Answers
Question 1: Which document formally defines the agreed-upon performance standards, uptime guarantees, and remedies for a vendor relationship?
- Master Service Agreement (MSA)
- Non-Disclosure Agreement (NDA)
- Service Level Agreement (SLA) (Correct answer)
- Statement of Work (SOW)
Correct answer: Service Level Agreement (SLA)
The SLA specifies measurable performance metrics, availability targets, and contractual remedies when those standards are not met.
Question 2: A vendor that handles sensitive health insurance data for a financial institution experiences a data breach. Under HIPAA, who bears primary responsibility for notifying affected individuals?
- The vendor as the Business Associate bears sole responsibility
- The financial institution as the Covered Entity bears primary notification responsibility, though the Business Associate must also notify the Covered Entity promptly (Correct answer)
- The state insurance commissioner handles all notifications
- No notification is required if the breach affected fewer than 500 individuals
Correct answer: The financial institution as the Covered Entity bears primary notification responsibility, though the Business Associate must also notify the Covered Entity promptly
Under HIPAA, the Covered Entity is responsible for notifying affected individuals; the Business Associate must notify the Covered Entity within 60 days of discovering the breach.
Question 3: What does 'inherent risk' mean in the context of a vendor risk assessment?
- The risk level after all controls and mitigations have been applied
- The risk level that exists based on the nature of the vendor relationship before considering any controls (Correct answer)
- The risk that a vendor will inherit another company's liabilities
- The contractual risk of a vendor exiting the relationship unexpectedly
Correct answer: The risk level that exists based on the nature of the vendor relationship before considering any controls
Inherent risk reflects the baseline exposure from a vendor relationship based on factors like data access and criticality, before controls are factored in.
Question 4: Which of the following BEST represents a leading practice for managing geographic concentration risk in a vendor portfolio?
- Concentrating all critical vendors in a single low-cost region to reduce expenses
- Diversifying critical vendors across multiple geographic regions and requiring multi-region data backup from cloud vendors (Correct answer)
- Selecting only domestic vendors for all services regardless of cost
- Relying on vendor-provided geographic redundancy assurances without independent verification
Correct answer: Diversifying critical vendors across multiple geographic regions and requiring multi-region data backup from cloud vendors
Geographic diversification across vendors and requiring vendors to maintain multi-region resilience protects against regional disruptions such as natural disasters or political instability.
Question 5: Which contractual provision MOST directly protects an organization if a vendor becomes insolvent?
- Most Favored Nation (MFN) pricing clause
- Termination for convenience clause
- Software escrow arrangement for source code or data custody (Correct answer)
- Automatic renewal clause
Correct answer: Software escrow arrangement for source code or data custody
Escrow arrangements ensure that critical software, code, or data can be accessed by the client if the vendor ceases operations, preserving business continuity.
Question 6: What is the MAIN risk governance function of a third-party risk committee at the enterprise level?
- Negotiating vendor contract terms directly with suppliers
- Providing oversight, setting risk appetite for vendor relationships, and making escalated decisions on high-risk vendor exceptions (Correct answer)
- Conducting vendor site visits and technical audits
- Managing day-to-day vendor relationship communications
Correct answer: Providing oversight, setting risk appetite for vendor relationships, and making escalated decisions on high-risk vendor exceptions
A TPRM committee's primary role is governance — setting policy, defining risk appetite, and resolving exceptions that exceed operational-level authority.
Question 7: An operational risk executive is building a vendor risk dashboard for the board. Which KRI (Key Risk Indicator) would be MOST meaningful for board-level oversight?
- Number of vendor invoices processed per month
- Percentage of critical vendors with overdue risk assessments or unresolved high findings (Correct answer)
- Total number of vendor contracts signed in the current fiscal year
- Average vendor response time to questionnaire submissions
Correct answer: Percentage of critical vendors with overdue risk assessments or unresolved high findings
Boards need indicators that signal emerging risk exposure; critical vendors with overdue reviews or open high findings represent unmanaged tail risk requiring attention.
Which document formally defines the agreed-upon performance standards, uptime guarantees, and remedies for a vendor relationship?