CTPRP Regulatory Requirements and Industry Standards for Third-Party Risk — Questions and Answers
Question 1: The OCC Bulletin 2013-29 (and its 2020 FAQ update) primarily governs third-party risk management for:
- All U.S. publicly traded companies subject to SEC reporting
- National banks and federal savings associations supervised by the Office of the Comptroller of the Currency (Correct answer)
- Technology companies that sell software to the federal government
- Healthcare organizations subject to HIPAA privacy requirements
Correct answer: National banks and federal savings associations supervised by the Office of the Comptroller of the Currency
OCC Bulletin 2013-29 is the primary third-party risk management guidance for national banks and federal savings associations (OCC-regulated institutions). It establishes a risk management lifecycle — planning, due diligence, contract negotiation, ongoing monitoring, termination — and is a foundational regulatory reference in U.S. financial services TPRM.
Question 2: Under GDPR, when a company in the EU transfers personal data to a third-party vendor located outside the EU, which mechanism is commonly used to ensure adequate data protection?
- A purchase order referencing the vendor's privacy policy
- Standard Contractual Clauses (SCCs) approved by the European Commission (Correct answer)
- A self-certification letter from the vendor's legal team
- Registration of the transfer with the local chamber of commerce
Correct answer: Standard Contractual Clauses (SCCs) approved by the European Commission
Standard Contractual Clauses (SCCs) — pre-approved contract terms issued by the European Commission — are one of the primary legal mechanisms for transferring personal data from the EU to third parties in countries that lack an adequacy decision. They impose GDPR-equivalent obligations on the recipient vendor. Self-certifications and purchase orders do not satisfy this legal transfer requirement.
Question 3: The EU's Digital Operational Resilience Act (DORA), which became effective in January 2025, specifically requires financial entities to:
- Conduct annual cybersecurity awareness training for all employees
- Manage ICT third-party risk, including contractual requirements for critical ICT providers and oversight of cloud vendors (Correct answer)
- Publish their vendor list on a public-facing website for transparency
- Obtain government approval before signing contracts with non-EU technology vendors
Correct answer: Manage ICT third-party risk, including contractual requirements for critical ICT providers and oversight of cloud vendors
DORA mandates that EU financial entities manage information and communications technology (ICT) third-party risk systematically. It requires specific contractual provisions with ICT vendors, concentration risk assessments for critical ICT providers, incident reporting obligations, and participation in the oversight framework for designated Critical ICT Third-Party Providers (CTPPs).
Question 4: The Shared Assessments Standardized Information Gathering (SIG) questionnaire is designed to:
- Replace all other regulatory assessment requirements with a single approved form
- Provide a common, comprehensive tool for assessing vendor information security and privacy controls across multiple domains (Correct answer)
- Certify that a vendor meets ISO 27001 requirements without a separate audit
- Serve as a legally binding contract addendum for data processing activities
Correct answer: Provide a common, comprehensive tool for assessing vendor information security and privacy controls across multiple domains
The SIG is a standardized questionnaire maintained by Shared Assessments (the body that administers the CTPRP credential) that covers 19+ control areas including cybersecurity, privacy, BC/DR, and physical security. It is designed to reduce duplicative assessment efforts for vendors by providing a common framework, but it does not replace regulatory assessments, provide certification, or serve as a legal contract.
Question 5: Under the FFIEC IT Examination Handbook guidance on third-party relationships, which of the following is considered a 'critical activity' requiring enhanced oversight?
- Janitorial services contracted for bank branch offices
- Core banking system processing outsourced to a third-party service provider (Correct answer)
- Annual holiday card printing outsourced to a local print shop
- Catering services for the bank's annual shareholder meeting
Correct answer: Core banking system processing outsourced to a third-party service provider
The FFIEC guidance defines 'critical activities' as those significant to the financial institution's financial condition, operations, or customer data. Core banking system processing — which handles transactions, accounts, and sensitive financial data — is the archetypal example. Janitorial, printing, and catering services do not involve critical financial operations or sensitive data.
Question 6: When a vendor holds a SOC 2 Type II report, which party is responsible for reviewing the 'complementary user entity controls' (CUECs) listed in the report?
- The external auditor who issued the SOC 2 report
- The client organization relying on the vendor, to confirm those controls are implemented on its own side (Correct answer)
- The vendor's internal audit team
- The AICPA, which governs SOC reporting standards
Correct answer: The client organization relying on the vendor, to confirm those controls are implemented on its own side
CUECs are controls that the vendor's SOC 2 auditor has identified as necessary at the client (user entity) side to achieve the stated control objectives. The vendor's SOC 2 does not test these — the client organization must verify it has implemented them. A third-party risk professional reviewing a SOC 2 must read the CUECs and confirm the organization's side of the control equation is in place.
The OCC Bulletin 2013-29 (and its 2020 FAQ update) primarily governs third-party risk management for: