Risk Management in Procurement Flashcards
7 cards from real CPP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management in Procurement flashcards as text
Which procurement risk is MOST directly mitigated by requiring suppliers to maintain business continuity plans (BCPs)?
Answer: Supply disruption risk due to unexpected events
A supplier BCP ensures the supplier has documented procedures to maintain operations or recover quickly from disruptions, reducing supply interruption risk for the buyer.
When a contract contains an 'indemnification clause,' it means:
Answer: One party agrees to hold the other harmless for specified losses or liabilities
An indemnification clause requires one party to compensate the other for losses, damages, or legal costs arising from specified circumstances.
In risk-adjusted total cost of ownership (TCO), which of the following is an example of a hidden risk cost?
Answer: Cost of supply disruption including production downtime and expediting fees
TCO analysis should incorporate risk-adjusted costs like potential downtime, quality failures, and emergency sourcing expenses beyond the unit purchase price.
Which of the following scenarios BEST illustrates 'demand risk' in procurement?
Answer: Sales forecasts are inaccurate, leading to excess or insufficient inventory
Demand risk occurs when actual consumption deviates significantly from forecasts, creating either excess inventory costs or stockouts.
A procurement team uses a 'risk appetite statement' primarily to:
Answer: Establish the level of risk the organization is willing to accept in pursuit of its objectives
A risk appetite statement formally documents how much risk leadership is prepared to tolerate, guiding procurement decisions on sourcing strategies and contract terms.
Which type of supplier risk is BEST addressed through cybersecurity assessments and data protection agreements?
Answer: Information security and data breach risk
As suppliers handle sensitive buyer data and systems, cybersecurity assessments and contractual data protection obligations mitigate the risk of breaches.
Which of the following is the CORRECT sequence for the risk management process in procurement?
Answer: Identify → Assess → Mitigate → Monitor
The standard risk management process follows: identify risks, assess their likelihood and impact, implement mitigation strategies, then monitor continuously.