Third-Party and Vendor Risk Management Flashcards
7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Third-Party and Vendor Risk Management flashcards as text
What is the primary purpose of a third-party risk management (TPRM) program?
Answer: To identify, assess, and mitigate risks introduced by external vendors and service providers
TPRM programs are designed to systematically identify, assess, and manage risks that arise from relationships with external vendors and service providers.
Which of the following best describes 'fourth-party risk' in vendor risk management?
Answer: Risk posed by the subcontractors or suppliers used by your direct vendors
Fourth-party risk refers to risks posed by the subcontractors or suppliers of your direct (third-party) vendors, extending risk visibility beyond direct relationships.
What is vendor tiering classification primarily used for in a TPRM program?
Answer: Determining the appropriate level of due diligence and oversight based on risk exposure
Vendor tiering helps organizations apply proportionate due diligence and oversight, directing the most rigorous scrutiny toward vendors that present the greatest risk.
What is the purpose of a right-to-audit clause in a vendor contract?
Answer: To permit the organization to inspect vendor operations and verify compliance with contractual obligations
A right-to-audit clause grants the contracting organization authority to inspect and verify a vendor's controls, processes, and compliance with agreed-upon obligations.
Which risk category is most directly associated with a critical vendor experiencing financial insolvency?
Answer: Vendor exit and service continuity risk
Vendor insolvency creates exit and continuity risk because it threatens the ongoing delivery of critical services or products that the organization depends on.
What is a key indicator that an organization may have excessive concentration risk in its vendor portfolio?
Answer: Over-reliance on a single vendor for the delivery of critical business services
Concentration risk arises when excessive dependency is placed on a single vendor, creating significant vulnerability if that vendor fails, underperforms, or exits the market.
In TPRM, what does the term 'vendor lifecycle management' encompass?
Answer: Overseeing vendor relationships from initial due diligence through offboarding and termination
Vendor lifecycle management covers all stages of a vendor relationship, including selection, due diligence, onboarding, ongoing monitoring, and offboarding.