โ† All CRA Flashcard Decks

Third-Party and Vendor Risk Management Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Third-Party and Vendor Risk Management flashcards as text
  1. Which of the following items is typically included in a vendor due diligence questionnaire (DDQ)?

    Answer: Information on security controls, financial stability, and regulatory compliance posture

    DDQs gather information on security practices, financial health, and compliance posture to comprehensively assess the risks a vendor introduces.

  2. What is the recommended review frequency for high-risk vendor relationships according to leading TPRM practices?

    Answer: At least annually, with more frequent reviews based on elevated risk or material changes

    High-risk vendor relationships require at least annual reviews, with increased frequency triggered by changes in the vendor's risk profile, ownership, or operational circumstances.

  3. Which certification is most commonly accepted as evidence of a vendor's information security controls effectiveness over time?

    Answer: SOC 2 Type II examination report

    SOC 2 Type II reports provide evidence that a vendor's security, availability, and confidentiality controls operated effectively over a defined reporting period.

  4. What does 'inherent risk' represent in a third-party risk assessment?

    Answer: The level of risk that exists before any controls or mitigations are in place

    Inherent risk is the baseline level of risk present before any controls, mitigations, or countermeasures are considered or applied.

  5. What is the primary purpose of an exit strategy in third-party risk management?

    Answer: To ensure the smooth and orderly transition of services if a vendor relationship must be terminated

    Exit strategies protect business continuity by planning for the orderly transition of services and data in the event a vendor relationship must unexpectedly end.

  6. Which U.S. regulatory guidance specifically requires financial institutions to conduct comprehensive due diligence on critical third-party service providers?

    Answer: OCC Bulletin 2013-29 on Third-Party Relationships

    OCC Bulletin 2013-29 provides comprehensive guidance for national banks on managing risks in third-party relationships, including robust due diligence requirements for critical vendors.

  7. What is a vendor onboarding risk assessment primarily concerned with evaluating?

    Answer: Whether a prospective vendor meets the organization's risk threshold criteria before engagement begins

    Onboarding risk assessment evaluates prospective vendors against established risk criteria to determine whether the relationship is acceptable before a formal contract is signed.

Third-Party and Vendor Risk Management Flashcards โ€” CRA Study Cards with Answers