CTPRP Ongoing Monitoring and Continuous Oversight — Questions and Answers
Question 1: Which factor should MOST influence the frequency of ongoing monitoring reviews for a third-party vendor?
- The vendor's inherent risk tier assigned during initial onboarding (Correct answer)
- The date the vendor contract was last renewed
- The number of employees at the vendor organization
- The geographic location of the vendor's headquarters
Correct answer: The vendor's inherent risk tier assigned during initial onboarding
Ongoing monitoring frequency is driven primarily by the inherent risk tier. High-risk vendors (those with access to sensitive data, critical systems, or regulated functions) require more frequent reassessments than low-risk vendors. Contract renewal dates, headcount, and geography are secondary or irrelevant without a risk-tier context.
Question 2: A vendor that previously scored 'low risk' in its initial due diligence assessment has just disclosed a major data breach affecting another client. What is the MOST appropriate immediate action?
- Wait until the next scheduled annual review to reassess the vendor
- Terminate the contract immediately without further investigation
- Trigger an out-of-cycle risk reassessment and request an incident report from the vendor (Correct answer)
- Notify the vendor's regulator directly on behalf of your organization
Correct answer: Trigger an out-of-cycle risk reassessment and request an incident report from the vendor
A material adverse event — such as a data breach — is a recognized trigger for an out-of-cycle reassessment. The organization must quickly understand whether the breach affects its own data or services before deciding on next steps. Waiting for an annual review ignores an emerging risk; immediate termination without investigation is premature.
Question 3: Key Risk Indicators (KRIs) used in continuous vendor monitoring are BEST described as:
- Lagging metrics that document losses already incurred from vendor failures
- Forward-looking metrics that signal rising risk before an adverse event occurs (Correct answer)
- Audit findings issued after an on-site examination of the vendor
- Contractual penalties triggered when a vendor misses an SLA
Correct answer: Forward-looking metrics that signal rising risk before an adverse event occurs
KRIs are predictive, forward-looking indicators designed to warn that risk is increasing before an adverse event materializes. They differ from Key Performance Indicators (KPIs), which measure outcomes, and from audit findings or SLA penalties, which are reactive.
Question 4: Which of the following is a recognized TRIGGER for an unscheduled reassessment of a third-party vendor?
- The vendor completes its ISO 27001 annual surveillance audit
- A new executive sponsor is assigned internally to oversee the vendor relationship
- The vendor is acquired by or merges with another company (Correct answer)
- The vendor's contract moves into the final year of its term
Correct answer: The vendor is acquired by or merges with another company
A merger or acquisition of the vendor is a classic trigger for an out-of-cycle reassessment because it can fundamentally change the vendor's ownership, controls, financial stability, and subcontractor relationships. Completing a routine audit, internal sponsor changes, or entering a final contract year do not by themselves constitute material risk events.
Question 5: What is the PRIMARY purpose of maintaining a vendor inventory as part of an ongoing monitoring program?
- To satisfy annual external audit requirements imposed by the firm's auditors
- To enable risk-tiered oversight and ensure no vendor relationship goes unmonitored (Correct answer)
- To calculate the total cost of vendor relationships for budget planning
- To provide marketing teams with a list of approved technology partners
Correct answer: To enable risk-tiered oversight and ensure no vendor relationship goes unmonitored
A complete, accurate vendor inventory is foundational to third-party risk management because you cannot monitor what you cannot see. It allows the organization to apply risk-tiered controls to every vendor, preventing gaps in oversight. While an inventory may satisfy audit requirements as a byproduct, risk visibility is the primary driver.
Question 6: Which monitoring approach is MOST appropriate for a critical vendor providing core payment processing services?
- Annual self-assessment questionnaire with no follow-up validation
- Continuous automated monitoring supplemented by periodic on-site assessments (Correct answer)
- Biennial document review conducted by a junior analyst
- Monitoring only when contractual SLAs are reported as breached
Correct answer: Continuous automated monitoring supplemented by periodic on-site assessments
Critical vendors warrant the most rigorous monitoring. Combining automated, real-time signals (e.g., threat intelligence feeds, uptime monitoring) with periodic deeper assessments — including on-site reviews — provides the layered assurance appropriate for high-risk, high-criticality relationships. Annual self-assessments alone are insufficient for critical vendors.
Which factor should MOST influence the frequency of ongoing monitoring reviews for a third-party vendor?