โ† All CRA Flashcard Decks

Third-Party and Vendor Risk Management Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Third-Party and Vendor Risk Management flashcards as text
  1. What is the primary purpose of a vendor scorecard in ongoing vendor relationship management?

    Answer: To continuously measure vendor performance against defined KPIs and risk metrics

    Vendor scorecards provide a structured mechanism to track ongoing performance against KPIs and risk metrics, enabling proactive identification of deteriorating vendor relationships.

  2. Which strategy best mitigates the risk of vendor lock-in for a critical service?

    Answer: Diversifying the vendor portfolio and ensuring data portability and interoperability

    Vendor lock-in risk is best mitigated through portfolio diversification, maintaining data portability, and ensuring interoperability with alternative providers.

  3. How should an organization respond when a critical vendor notifies it of a significant data breach?

    Answer: Activate the incident response plan, assess the impact on the organization, and coordinate remediation with the vendor

    A structured incident response involving impact assessment and coordinated remediation with the vendor is essential to manage the breach's effect on the organization effectively.

  4. What does 'residual risk' represent after vendor controls and mitigations have been applied?

    Answer: The level of risk that remains after all identified controls and mitigations have been applied

    Residual risk is the risk exposure that persists even after all applicable controls, mitigations, and risk transfer mechanisms have been implemented.

  5. Which practice is considered a best approach for managing geographic concentration risk in the vendor portfolio?

    Answer: Distributing critical vendor relationships across multiple geographic regions to reduce regional exposure

    Distributing vendor relationships geographically reduces exposure to regional disruptions such as natural disasters, geopolitical instability, or localized regulatory changes.

  6. What is the role of 'vendor risk appetite' in a TPRM program?

    Answer: It establishes the level of third-party risk the organization is willing to accept in pursuit of its objectives

    Vendor risk appetite defines the boundaries of acceptable third-party risk exposure, guiding decision-making throughout the entire vendor lifecycle from selection to offboarding.

  7. Which of the following represents the most significant challenge in managing nth-party (extended supply chain) risk?

    Answer: Limited visibility into the risk controls and practices of sub-vendors beyond direct vendor relationships

    Extended supply chain risk is inherently challenging because organizations have limited visibility into and control over the risk management practices of sub-vendors and lower-tier suppliers.