CTPRP Risk Reporting, Governance, and Program Management — Questions and Answers
Question 1: Which body within an organization typically has ULTIMATE accountability for the third-party risk management program?
- The procurement department, because it owns vendor contracts
- The Board of Directors or a delegated committee such as the Risk Committee (Correct answer)
- The IT department, because most vendor risk is technology-related
- The individual business lines that sponsor each vendor relationship
Correct answer: The Board of Directors or a delegated committee such as the Risk Committee
Governance accountability for enterprise risk programs — including TPRM — rests at the Board or its delegated committee (e.g., Audit and Risk Committee). The Board sets risk appetite and expects management to report on TPRM program effectiveness. Procurement, IT, and business lines have operational roles, but ultimate accountability is at the governance level.
Question 2: A 'risk appetite statement' in the context of third-party risk management defines:
- The maximum number of vendors the organization will onboard in a fiscal year
- The level and types of vendor-related risk the organization is willing to accept in pursuit of its objectives (Correct answer)
- The dollar threshold above which vendor contracts require board approval
- The minimum SLA performance score a vendor must achieve to remain on the approved list
Correct answer: The level and types of vendor-related risk the organization is willing to accept in pursuit of its objectives
A risk appetite statement articulates how much and what kinds of third-party risk the organization is prepared to tolerate. It guides decisions such as which vendor tiers receive enhanced due diligence, when to reject a vendor despite business pressure, and how aggressively to pursue remediation. It is a governance document, not a procurement threshold or SLA benchmark.
Question 3: Which metric would be MOST useful to include in a quarterly TPRM dashboard presented to senior management?
- The average tenure of the TPRM team's analysts
- The number of high-risk vendors with overdue remediation items (Correct answer)
- The total number of vendor invoices processed in the quarter
- The vendor's employee satisfaction scores from internal surveys
Correct answer: The number of high-risk vendors with overdue remediation items
Senior leadership needs actionable risk intelligence. The number of high-risk vendors with overdue remediation items is a direct indicator of unresolved risk exposure that may require executive escalation or resource allocation. Analyst tenure, invoice volumes, and vendor employee satisfaction do not convey meaningful risk posture to a risk dashboard audience.
Question 4: The 'offboarding' phase of the vendor lifecycle is important to third-party risk management primarily because:
- It provides an opportunity to renegotiate pricing for future contracts
- It ensures the organization's data is returned or destroyed and access is revoked when a vendor relationship ends (Correct answer)
- It allows the TPRM team to close the vendor file and meet document retention requirements
- It notifies the vendor's regulator that the relationship has concluded
Correct answer: It ensures the organization's data is returned or destroyed and access is revoked when a vendor relationship ends
Offboarding is a critical risk control point. When a vendor relationship ends, the organization must ensure all data (including sensitive customer or proprietary data) is securely returned or destroyed per contractual and regulatory requirements, and that all system access credentials are revoked. Failure to manage offboarding can leave data exposed or former vendors with ongoing access.
Question 5: An organization uses a tiered vendor classification system (e.g., Tier 1 = Critical, Tier 2 = High, Tier 3 = Low). What is the PRIMARY benefit of this approach?
- It simplifies the procurement process by standardizing contract templates
- It allows TPRM resources and controls to be proportionally allocated based on the risk each vendor presents (Correct answer)
- It ensures all vendors are assessed using an identical questionnaire regardless of their risk level
- It satisfies ISO 27001 Annex A control requirements for supplier relationships
Correct answer: It allows TPRM resources and controls to be proportionally allocated based on the risk each vendor presents
Tiering allows risk-proportionate resource allocation — applying more rigorous (and expensive) due diligence, more frequent monitoring, and stronger contractual protections to vendors that present greater risk. Applying the same level of scrutiny to every vendor would be impractical and inefficient. Tiering is a foundational TPRM program design decision, not primarily a procurement or compliance mechanism.
Question 6: When a business unit 'inherits' responsibility for a vendor previously managed by another team, which step is MOST critical from a TPRM perspective?
- Renegotiating the vendor's pricing to reflect the new business unit's budget
- Verifying the vendor's current risk assessment is up to date and transferring formal risk ownership (Correct answer)
- Issuing a press release announcing the new internal ownership structure
- Immediately terminating the vendor to start fresh with a new procurement process
Correct answer: Verifying the vendor's current risk assessment is up to date and transferring formal risk ownership
When vendor relationship ownership transfers, the TPRM program must ensure that risk ownership — and accountability for monitoring and remediation — formally transfers as well. The incoming team must confirm the vendor's risk documentation is current and that they understand any open issues. Without this handoff, vendors can fall into monitoring gaps.
Which body within an organization typically has ULTIMATE accountability for the third-party risk management program?