CRA Third-Party and Vendor Risk Management 2 — Questions and Answers
Question 1: Which of the following items is typically included in a vendor due diligence questionnaire (DDQ)?
- Vendor's marketing strategy and customer acquisition costs
- Information on security controls, financial stability, and regulatory compliance posture (Correct answer)
- Details about the vendor's executive compensation and bonus structure
- The vendor's historical stock price and analyst ratings
Correct answer: Information on security controls, financial stability, and regulatory compliance posture
DDQs gather information on security practices, financial health, and compliance posture to comprehensively assess the risks a vendor introduces.
Question 2: What is the recommended review frequency for high-risk vendor relationships according to leading TPRM practices?
- Once at contract inception and never again unless problems arise
- Every five years aligned with standard contract renewal cycles
- At least annually, with more frequent reviews based on elevated risk or material changes (Correct answer)
- Only when a regulatory examination or security incident occurs
Correct answer: At least annually, with more frequent reviews based on elevated risk or material changes
High-risk vendor relationships require at least annual reviews, with increased frequency triggered by changes in the vendor's risk profile, ownership, or operational circumstances.
Question 3: Which certification is most commonly accepted as evidence of a vendor's information security controls effectiveness over time?
- ISO 9001 Quality Management certification
- SOC 2 Type II examination report (Correct answer)
- PCI DSS Level 4 self-assessment questionnaire
- GDPR Article 42 certification
Correct answer: SOC 2 Type II examination report
SOC 2 Type II reports provide evidence that a vendor's security, availability, and confidentiality controls operated effectively over a defined reporting period.
Question 4: What does 'inherent risk' represent in a third-party risk assessment?
- The risk remaining after all controls and mitigations are fully applied
- The level of risk that exists before any controls or mitigations are in place (Correct answer)
- The risk formally transferred to the vendor through contractual indemnification
- The risk identified exclusively during the vendor onboarding phase
Correct answer: The level of risk that exists before any controls or mitigations are in place
Inherent risk is the baseline level of risk present before any controls, mitigations, or countermeasures are considered or applied.
Question 5: What is the primary purpose of an exit strategy in third-party risk management?
- To negotiate lower contract prices at the time of renewal
- To ensure the smooth and orderly transition of services if a vendor relationship must be terminated (Correct answer)
- To immediately replace vendors who fail any security audit
- To document a vendor's decision to exit a particular service market
Correct answer: To ensure the smooth and orderly transition of services if a vendor relationship must be terminated
Exit strategies protect business continuity by planning for the orderly transition of services and data in the event a vendor relationship must unexpectedly end.
Question 6: Which U.S. regulatory guidance specifically requires financial institutions to conduct comprehensive due diligence on critical third-party service providers?
- GDPR Article 28 on data processor requirements
- OCC Bulletin 2013-29 on Third-Party Relationships (Correct answer)
- HIPAA Privacy Rule vendor provisions
- SOX Section 302 certification requirements
Correct answer: OCC Bulletin 2013-29 on Third-Party Relationships
OCC Bulletin 2013-29 provides comprehensive guidance for national banks on managing risks in third-party relationships, including robust due diligence requirements for critical vendors.
Question 7: What is a vendor onboarding risk assessment primarily concerned with evaluating?
- The vendor's pricing competitiveness relative to market benchmarks
- Whether a prospective vendor meets the organization's risk threshold criteria before engagement begins (Correct answer)
- Whether the vendor can process electronic payments and invoices efficiently
- The vendor's customer satisfaction scores and public reputation ratings
Correct answer: Whether a prospective vendor meets the organization's risk threshold criteria before engagement begins
Onboarding risk assessment evaluates prospective vendors against established risk criteria to determine whether the relationship is acceptable before a formal contract is signed.
Which of the following items is typically included in a vendor due diligence questionnaire (DDQ)?