CTPRP Regulatory Compliance and Vendor Governance 1 — Questions and Answers
Question 1: Which US federal law requires covered entities and their business associates to safeguard protected health information (PHI) shared with vendors?
- HIPAA (Correct answer)
- SOX
- GLBA
- FCRA
Correct answer: HIPAA
HIPAA requires covered entities to enter into Business Associate Agreements (BAAs) with vendors that access or process PHI, establishing mutual data protection obligations.
Question 2: Under the Gramm-Leach-Bliley Act (GLBA), what must financial institutions require from service providers who handle consumer financial data?
- Contractual safeguards and privacy obligations for consumer data (Correct answer)
- Proof of ISO 9001 certification
- Annual charity contributions
- A minimum of 500 employees
Correct answer: Contractual safeguards and privacy obligations for consumer data
GLBA's Safeguards Rule requires financial institutions to contractually obligate service providers to implement appropriate safeguards for customer financial data.
Question 3: What is the primary role of a Third-Party Risk Management (TPRM) policy within an organization?
- To establish the governance framework, roles, and standards for managing vendor risk (Correct answer)
- To list approved vendors for procurement teams
- To set employee salary guidelines for risk staff
- To define the organization's marketing strategy for vendor partnerships
Correct answer: To establish the governance framework, roles, and standards for managing vendor risk
A TPRM policy defines the governance structure, risk appetite, roles and responsibilities, and minimum standards that guide all third-party risk management activities organization-wide.
Question 4: Which body provides the CTPRP certification and sets the professional standards for third-party risk professionals in the US?
- Shared Assessments (Correct answer)
- ISACA
- ISC2
- CompTIA
Correct answer: Shared Assessments
Shared Assessments is the organization that administers the CTPRP certification and develops the tools and standards used by third-party risk professionals globally.
Question 5: What is the key purpose of a right-to-audit clause in a vendor contract?
- To allow the client organization to audit the vendor's controls and compliance (Correct answer)
- To give the vendor the right to audit the client's financials
- To permit third-party auditors to review the client's own employees
- To authorize government regulators to inspect vendor facilities on behalf of the client
Correct answer: To allow the client organization to audit the vendor's controls and compliance
A right-to-audit clause contractually reserves the client's ability to conduct or commission audits of the vendor's controls, ensuring ongoing accountability beyond self-attestation.
Question 6: Under GDPR, which role does a vendor typically hold when processing personal data on behalf of a US-based company serving EU residents?
- Data Processor (Correct answer)
- Data Controller
- Data Subject
- Data Custodian
Correct answer: Data Processor
Under GDPR, a vendor processing personal data solely under the instructions of a client organization is classified as a Data Processor, with specific obligations under Article 28.
Which US federal law requires covered entities and their business associates to safeguard protected health information (PHI) shared with vendors?