CRISC Third-Party and Vendor Risk Management 2 — Questions and Answers
Question 1: Concentration risk in third-party management occurs when:
- A single vendor provides services to multiple business units or critical functions (Correct answer)
- A vendor concentrates solely on one industry vertical
- Multiple vendors compete for the same contract
- An organization diversifies across too many vendors
Correct answer: A single vendor provides services to multiple business units or critical functions
Concentration risk arises when over-reliance on a single vendor means their failure could simultaneously disrupt multiple critical organizational functions.
Question 2: Under the shared responsibility model for cloud services, who is responsible for classifying and protecting customer data stored in the cloud?
- The cloud service provider exclusively
- The customer organization (Correct answer)
- A jointly appointed data governance committee
- The regulatory authority overseeing the organization
Correct answer: The customer organization
Under the shared responsibility model, the customer organization retains responsibility for data classification, access control, and data protection even when data resides in the cloud.
Question 3: What is the BEST approach for managing vendor risk when a vendor refuses to allow direct audits?
- Terminate the vendor immediately regardless of the business relationship
- Accept the vendor's word that their controls are adequate
- Require the vendor to provide third-party audit reports such as SOC 2 Type II (Correct answer)
- Reduce the contract value to reflect the increased risk
Correct answer: Require the vendor to provide third-party audit reports such as SOC 2 Type II
Independent third-party audit reports like SOC 2 Type II provide objective assurance of vendor control effectiveness when direct audits are not permitted.
Question 4: A vendor risk register should PRIMARILY contain:
- A list of vendors ranked by contract value
- Identified risks associated with each vendor, their likelihood, impact, and mitigating controls (Correct answer)
- A record of all vendor invoices and payment history
- Marketing contact information for each vendor
Correct answer: Identified risks associated with each vendor, their likelihood, impact, and mitigating controls
A vendor risk register documents risks per vendor alongside risk ratings and controls, enabling systematic tracking and management of third-party risk exposure.
Question 5: Which regulatory framework explicitly requires organizations to assess and manage third-party risks for financial institutions?
- COBIT 2019
- FFIEC IT Examination Handbook (Third-Party Relationships) (Correct answer)
- ISO 9001
- PMBOK Guide
Correct answer: FFIEC IT Examination Handbook (Third-Party Relationships)
The FFIEC IT Examination Handbook on Third-Party Relationships provides specific regulatory guidance for financial institutions on managing vendor and third-party risks.
Question 6: During a vendor security incident that affects your organization's data, what is the FIRST step the organization should take?
- Immediately terminate the vendor contract
- Activate the incident response plan and notify relevant internal stakeholders (Correct answer)
- Issue a public press release about the incident
- Wait for the vendor to fully resolve the incident before taking action
Correct answer: Activate the incident response plan and notify relevant internal stakeholders
Activating the incident response plan ensures a coordinated, timely response that limits further damage and fulfills regulatory notification obligations.
Question 7: What is the purpose of a Data Processing Agreement (DPA) in vendor contracts?
- To specify the technical architecture the vendor must use
- To define terms under which a vendor may process personal data on behalf of the organization (Correct answer)
- To allocate hardware procurement responsibilities between parties
- To establish vendor employee training schedules
Correct answer: To define terms under which a vendor may process personal data on behalf of the organization
A DPA legally defines the terms of personal data processing by a vendor acting as a data processor, a requirement under frameworks like GDPR and CCPA.
Concentration risk in third-party management occurs when: