CRISC Third-Party and Vendor Risk Management 1 — Questions and Answers
Question 1: Which activity is MOST important when onboarding a new critical third-party vendor?
- Reviewing the vendor's marketing materials
- Conducting a thorough due diligence risk assessment (Correct answer)
- Negotiating the lowest possible contract price
- Assigning an internal project manager to the relationship
Correct answer: Conducting a thorough due diligence risk assessment
Due diligence risk assessment is essential before onboarding critical vendors to identify security, financial, and operational risks they may introduce.
Question 2: A 'fourth-party risk' in vendor management refers to:
- Risk from the organization's internal fourth department
- Risk from subcontractors or suppliers used by your primary vendors (Correct answer)
- Risk arising from the fourth quarter of the fiscal year
- Risk from the fourth item on the vendor contract
Correct answer: Risk from subcontractors or suppliers used by your primary vendors
Fourth-party risk refers to the risk introduced by vendors that your direct (third-party) vendors rely upon, creating an extended supply chain risk.
Question 3: Which contract provision gives an organization the RIGHT to examine a vendor's controls and compliance posture?
- Indemnification clause
- Force majeure clause
- Right-to-audit clause (Correct answer)
- Limitation of liability clause
Correct answer: Right-to-audit clause
A right-to-audit clause contractually permits the organization to conduct audits or assessments of the vendor's security controls and compliance.
Question 4: When classifying vendors by risk tier, which factor is MOST relevant to assigning a vendor to the highest risk tier?
- The vendor's geographic headquarters location
- The volume of sensitive data the vendor accesses or processes (Correct answer)
- The length of the vendor relationship
- The number of employees the vendor has
Correct answer: The volume of sensitive data the vendor accesses or processes
Vendors who access or process significant volumes of sensitive or regulated data pose the greatest potential impact in a breach, warranting the highest risk tier.
Question 5: What is the PRIMARY purpose of a Service Level Agreement (SLA) in vendor risk management?
- To define ownership of intellectual property created during the engagement
- To set measurable performance and availability expectations that can be monitored (Correct answer)
- To establish the vendor's financial responsibility for data breaches
- To outline the marketing obligations of each party
Correct answer: To set measurable performance and availability expectations that can be monitored
SLAs define specific, measurable service performance targets, enabling the organization to monitor vendor compliance and hold vendors accountable.
Question 6: An organization terminates its relationship with a cloud vendor. Which action is MOST critical from a risk management perspective?
- Sending a formal termination letter with 30-day notice
- Ensuring all organizational data is securely retrieved and deleted from vendor systems (Correct answer)
- Publishing an announcement to notify stakeholders
- Issuing a final invoice for outstanding payments
Correct answer: Ensuring all organizational data is securely retrieved and deleted from vendor systems
Secure data retrieval and certified deletion prevents residual data exposure, which is the primary risk when offboarding a cloud vendor.
Question 7: Which metric is MOST useful for ongoing monitoring of a vendor's security risk posture?
- The vendor's annual revenue growth rate
- The number of years the vendor has been in business
- Frequency and severity of security incidents reported by the vendor (Correct answer)
- The vendor's employee satisfaction score
Correct answer: Frequency and severity of security incidents reported by the vendor
Security incident frequency and severity directly reflects the vendor's control effectiveness and their risk to the organization over time.
Which activity is MOST important when onboarding a new critical third-party vendor?