CRO Third-Party Risk Assessment 2 — Questions and Answers
Question 1: Which due diligence tier typically applies to a third-party vendor that processes protected health information (PHI) on behalf of a covered entity?
- Tier 1 — minimal review only
- Tier 2 — standard questionnaire
- Tier 3 — enhanced due diligence with on-site audit rights (Correct answer)
- No formal due diligence is required for sub-processors
Correct answer: Tier 3 — enhanced due diligence with on-site audit rights
Vendors handling PHI are classified as business associates under HIPAA and require enhanced due diligence, including audit rights and Business Associate Agreements.
Question 2: A CRO discovers a critical vendor has been acquired by a competitor. What is the FIRST risk management action to take?
- Immediately terminate the contract
- Re-evaluate the vendor's risk profile and assess concentration risk (Correct answer)
- Notify regulators of the ownership change
- Transfer all data to an alternate vendor without delay
Correct answer: Re-evaluate the vendor's risk profile and assess concentration risk
An ownership change triggers a re-assessment of the vendor's risk profile, including data access, service continuity, and potential conflicts of interest.
Question 3: What does 'nth-party risk' refer to in third-party risk management?
- Risk from vendors in countries outside the US
- Risk arising from a vendor's own subcontractors and their supply chain (Correct answer)
- Risk from vendors that serve more than N clients simultaneously
- Risk quantified using the Nth percentile loss model
Correct answer: Risk arising from a vendor's own subcontractors and their supply chain
Nth-party risk refers to risks introduced by sub-vendors, sub-processors, and the extended supply chain beyond the direct third party.
Question 4: Under the OCC's third-party risk management guidance, which activity requires the MOST stringent oversight?
- Purchasing standard office supplies
- Outsourcing a core banking function to a fintech partner (Correct answer)
- Engaging a temporary staffing agency for administrative roles
- Licensing commercially available anti-virus software
Correct answer: Outsourcing a core banking function to a fintech partner
The OCC requires the most stringent oversight for critical activities, especially outsourced core banking functions that could affect safety, soundness, or compliance.
Question 5: Which metric BEST measures the effectiveness of a third-party risk program over time?
- Total number of vendors onboarded
- Percentage of vendors with completed risk assessments within the review cycle (Correct answer)
- Average contract value across the vendor portfolio
- Number of vendor site visits conducted annually
Correct answer: Percentage of vendors with completed risk assessments within the review cycle
Assessment completion rate within the defined review cycle directly measures program effectiveness and identifies gaps in ongoing monitoring.
Question 6: A vendor's SOC 2 Type II report has a qualified opinion. What does this mean for the risk assessment?
- The vendor passed all control tests with minor exceptions
- One or more controls did not operate effectively during the audit period (Correct answer)
- The audit scope was limited to a subset of trust service criteria
- The report was issued after the standard 12-month review window
Correct answer: One or more controls did not operate effectively during the audit period
A qualified opinion in a SOC 2 Type II report indicates that auditors found exceptions where one or more controls failed to operate effectively during the period.
Question 7: Which contractual provision BEST protects an organization if a vendor suffers a data breach involving customer PII?
- Force majeure clause
- Right-to-audit clause combined with breach notification and indemnification provisions (Correct answer)
- Most-favored-nation pricing clause
- Automatic renewal clause with 30-day opt-out
Correct answer: Right-to-audit clause combined with breach notification and indemnification provisions
Right-to-audit, mandatory breach notification timelines, and indemnification together provide both preventive oversight and financial recourse after a breach.
Which due diligence tier typically applies to a third-party vendor that processes protected health information (PHI) on behalf of a covered entity?