CTPRP Regulatory Compliance and Vendor Governance 2 — Questions and Answers
Question 1: Which element of a vendor contract directly defines the performance standards the vendor must meet?
- Service-Level Agreement (SLA) (Correct answer)
- Non-Disclosure Agreement (NDA)
- Master Service Agreement (MSA)
- Statement of Work (SOW)
Correct answer: Service-Level Agreement (SLA)
An SLA specifies measurable performance metrics such as uptime, response time, and resolution times that the vendor is contractually obligated to maintain.
Question 2: What is the significance of PCI DSS compliance for a vendor handling payment card data?
- It confirms the vendor meets security standards required to store, process, or transmit cardholder data (Correct answer)
- It certifies the vendor as a preferred payment processor by Visa and Mastercard
- It exempts the vendor from SOC 2 audit requirements
- It indicates the vendor has no prior data breaches
Correct answer: It confirms the vendor meets security standards required to store, process, or transmit cardholder data
PCI DSS compliance demonstrates that the vendor has implemented the required controls to protect cardholder data, reducing the payment-related risk to organizations that share card data with them.
Question 3: In vendor governance, what does 'escalation path' refer to?
- The defined process for raising unresolved vendor issues to higher authority (Correct answer)
- The vendor's plan to grow its business with your organization
- The contract renewal negotiation process
- The vendor's internal promotion structure
Correct answer: The defined process for raising unresolved vendor issues to higher authority
An escalation path defines the steps and authorities involved when vendor performance issues, control failures, or contractual disputes cannot be resolved at the operational level.
Question 4: Which committee or group within an organization typically has oversight responsibility for the enterprise third-party risk management program?
- Risk Committee or Third-Party Risk Oversight Committee (Correct answer)
- IT Help Desk team
- Marketing leadership team
- Individual business unit procurement staff only
Correct answer: Risk Committee or Third-Party Risk Oversight Committee
A dedicated Risk Committee or Third-Party Risk Oversight Committee provides executive-level governance, ensuring TPRM is aligned with enterprise risk appetite and regulatory expectations.
Question 5: When a vendor is classified as 'critical,' what additional oversight is typically required beyond standard due diligence?
- Enhanced monitoring, executive engagement, and contingency planning (Correct answer)
- Only an annual questionnaire review
- A credit check and insurance verification
- Monthly marketing meetings
Correct answer: Enhanced monitoring, executive engagement, and contingency planning
Critical vendors receive heightened oversight including more frequent assessments, senior-level relationship management, and tested contingency or exit plans due to their impact on business operations.
Question 6: What does 'vendor offboarding' in a TPRM program primarily ensure?
- That access is revoked and data is returned or destroyed when a vendor relationship ends (Correct answer)
- That the vendor receives a positive reference letter
- That the vendor's invoices are paid in full before separation
- That the vendor is added to a preferred vendor list for future use
Correct answer: That access is revoked and data is returned or destroyed when a vendor relationship ends
Vendor offboarding ensures that all system access is terminated, data obligations are fulfilled (returned or securely destroyed), and residual risks are managed when a vendor relationship concludes.
Which element of a vendor contract directly defines the performance standards the vendor must meet?