CTPRP Business Continuity and Resiliency Risk — Questions and Answers
Question 1: What is the PRIMARY purpose of reviewing a vendor's Business Continuity Plan (BCP) during third-party due diligence?
- To confirm the vendor meets ISO 27001 certification requirements
- To assess whether the vendor can continue delivering services during a disruptive event (Correct answer)
- To verify that the vendor has adequate Directors & Officers (D&O) insurance
- To determine if the vendor's employees have signed non-disclosure agreements
Correct answer: To assess whether the vendor can continue delivering services during a disruptive event
The BCP review is conducted to understand whether a vendor has credible, tested plans for maintaining service delivery — or recovering it rapidly — when faced with disasters, system failures, or other disruptions. This directly protects the client organization from downstream operational risk when a critical vendor is impacted.
Question 2: A vendor states its Recovery Time Objective (RTO) is 4 hours. What does this mean?
- The vendor promises to back up data every 4 hours
- The vendor commits to restoring services within 4 hours of a declared disaster (Correct answer)
- The vendor will notify you of an outage within 4 hours
- The vendor's contract penalty period begins after 4 hours of downtime
Correct answer: The vendor commits to restoring services within 4 hours of a declared disaster
RTO is the maximum acceptable time between a service disruption and the restoration of normal operations. A 4-hour RTO means the vendor commits to having services back up within 4 hours of invoking their disaster recovery plan. It differs from RPO (Recovery Point Objective), which addresses how much data loss is acceptable.
Question 3: Vendor concentration risk occurs when:
- A single vendor provides services in multiple geographic regions
- An organization relies on one vendor (or a small group) for a critical function with no viable alternatives (Correct answer)
- A vendor charges higher prices due to market dominance
- Multiple vendors compete for the same contract, creating bidding pressure
Correct answer: An organization relies on one vendor (or a small group) for a critical function with no viable alternatives
Concentration risk arises when dependence on a single vendor — or a few vendors — for a critical service creates an outsized operational risk if that vendor fails, exits the market, or cannot perform. Regulators increasingly require organizations to identify and mitigate concentration risk through diversification strategies or robust contingency plans.
Question 4: Which of the following provides the STRONGEST assurance that a vendor's disaster recovery plan will work when needed?
- A written attestation from the vendor's CTO that the plan has been reviewed
- Evidence that the vendor completed a full failover test within the last 12 months (Correct answer)
- The existence of a documented DR plan filed in the vendor's policy repository
- The vendor's purchase of DR software licenses
Correct answer: Evidence that the vendor completed a full failover test within the last 12 months
Documented plans and attestations confirm intent, but only tested plans provide evidence of actual operational effectiveness. A full failover test — where systems actually cut over to backup infrastructure — validates that the plan works in practice. Untested DR plans frequently fail during real events due to undetected gaps.
Question 5: Fourth-party risk refers to:
- Risk from the fourth vendor on your organization's approved vendor list
- Risk introduced by your vendor's own subcontractors and suppliers (Correct answer)
- The fourth category of inherent risk in your risk scoring model
- Risk that materializes in the fourth year of a multi-year vendor contract
Correct answer: Risk introduced by your vendor's own subcontractors and suppliers
Fourth parties are the vendors that your vendors rely on — their subcontractors, technology providers, and supply chain partners. A breach or failure at a fourth party can cascade to your third party and then to your organization, even though you have no direct relationship. Mature TPRM programs assess and monitor fourth-party exposure for critical vendors.
Question 6: When should an organization's own Business Impact Analysis (BIA) inform its third-party risk program?
- Only when a vendor has already experienced a disruption
- To identify which vendor services are critical and require stronger BCP/DR scrutiny (Correct answer)
- To set vendor pricing negotiations based on service criticality
- Only for vendors located in geographic regions prone to natural disasters
Correct answer: To identify which vendor services are critical and require stronger BCP/DR scrutiny
An internal BIA identifies which business processes are most critical and time-sensitive. Those findings directly inform third-party risk management by flagging which vendor services support critical processes — and therefore which vendor BCP/DR capabilities deserve the most rigorous scrutiny and the tightest RTO/RPO requirements.
What is the PRIMARY purpose of reviewing a vendor's Business Continuity Plan (BCP) during third-party due diligence?