CRO Third-Party Risk Assessment 3 — Questions and Answers
Question 1: A risk assessment reveals that two critical vendors share the same data center facility. Which risk type does this PRIMARILY represent?
- Reputational risk
- Concentration risk (Correct answer)
- Liquidity risk
- Model risk
Correct answer: Concentration risk
Shared infrastructure creates concentration risk because a single facility failure could simultaneously disable multiple critical vendors.
Question 2: Which standard provides a globally recognized framework specifically for information security controls that is commonly used to evaluate third-party vendors?
- COSO ERM
- ISO/IEC 27001 (Correct answer)
- Basel III
- SSAE 18
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is the international standard for information security management systems and is widely used to evaluate vendor security posture.
Question 3: During vendor onboarding, a security assessment reveals that a critical vendor does not encrypt data at rest. What is the MOST appropriate CRO response?
- Proceed with onboarding and document the risk
- Require the vendor to remediate the gap before go-live or escalate for senior risk acceptance (Correct answer)
- Automatically disqualify the vendor from future consideration
- Transfer the risk to the vendor via contract language alone
Correct answer: Require the vendor to remediate the gap before go-live or escalate for senior risk acceptance
Identified security gaps should be remediated before go-live; if business need is urgent, unresolved gaps require formal risk acceptance by senior leadership, not just documentation.
Question 4: What is the purpose of a vendor risk tiering model?
- To rank vendors by contract value for negotiation leverage
- To allocate due diligence effort proportionally based on potential impact and likelihood of harm (Correct answer)
- To establish vendor payment priority during financial stress
- To determine which vendors qualify for volume discounts
Correct answer: To allocate due diligence effort proportionally based on potential impact and likelihood of harm
Risk tiering directs limited oversight resources toward vendors that pose the greatest potential risk, ensuring proportional due diligence.
Question 5: Which scenario BEST illustrates a 'vendor lock-in' risk?
- A vendor raises prices by 5% at contract renewal
- Proprietary data formats and migration costs make switching vendors prohibitively expensive (Correct answer)
- A vendor's employee leaves and joins a competitor
- A vendor fails to meet an SLA for two consecutive months
Correct answer: Proprietary data formats and migration costs make switching vendors prohibitively expensive
Vendor lock-in occurs when proprietary systems, data formats, or switching costs prevent an organization from moving to an alternative provider.
Question 6: A CRO is designing a continuous monitoring program for high-risk vendors. Which data source provides the MOST timely indicator of emerging vendor financial distress?
- Annual audited financial statements
- Credit rating changes and news alerts from financial intelligence services (Correct answer)
- Quarterly vendor self-assessments
- Biennial on-site audits
Correct answer: Credit rating changes and news alerts from financial intelligence services
Real-time credit rating changes and financial news alerts provide timely early warning of vendor financial distress, unlike periodic audit or self-assessment cycles.
Question 7: Under DORA (Digital Operational Resilience Act), what must EU financial entities maintain regarding ICT third-party providers?
- A list of all vendors with annual revenue over €1M
- A register of information on all contractual arrangements with ICT third-party service providers (Correct answer)
- Escrow accounts for all critical vendor payments
- Physical copies of all vendor contracts stored off-site
Correct answer: A register of information on all contractual arrangements with ICT third-party service providers
DORA Article 28 requires financial entities to maintain and regularly update a complete register of all contractual arrangements with ICT third-party service providers.
A risk assessment reveals that two critical vendors share the same data center facility.
Which risk type does this PRIMARILY represent?