CTPRP Third-Party Risk Assessment and Due Diligence 1 — Questions and Answers
Question 1: Which document is most commonly used as the foundation for third-party risk assessments in the US financial sector?
- Standardized Information Gathering (SIG) questionnaire (Correct answer)
- ISO 9001 checklist
- GDPR Article 28 template
- NIST SP 800-37 form
Correct answer: Standardized Information Gathering (SIG) questionnaire
The SIG questionnaire, developed by Shared Assessments, is the industry standard tool for gathering third-party risk information in the financial and other regulated sectors.
Question 2: What is the primary purpose of inherent risk scoring during vendor due diligence?
- To prioritize vendors by potential risk before controls are considered (Correct answer)
- To calculate the vendor's annual contract value
- To determine the vendor's credit rating
- To assess the vendor's marketing capabilities
Correct answer: To prioritize vendors by potential risk before controls are considered
Inherent risk scoring evaluates the risk a third party poses based on the nature of the engagement, independent of any controls the vendor may have in place.
Question 3: During onboarding due diligence, which factor most increases a vendor's risk tier?
- Access to sensitive customer data or critical systems (Correct answer)
- Vendor's geographic location within the US
- Number of employees at the vendor company
- Vendor's length of time in business
Correct answer: Access to sensitive customer data or critical systems
Access to sensitive data or critical systems is the primary driver for escalating a vendor to a higher risk tier requiring more rigorous due diligence.
Question 4: What is a 'fourth-party risk' in the context of third-party risk management?
- Risk posed by your vendor's subcontractors or suppliers (Correct answer)
- Risk from regulatory bodies auditing your organization
- Risk from competitors accessing your vendor data
- Risk from internal employees misusing vendor systems
Correct answer: Risk posed by your vendor's subcontractors or suppliers
Fourth-party risk refers to the risk exposure that arises from the subcontractors and service providers used by your direct (third-party) vendors.
Question 5: Which assessment type involves an on-site visit to the vendor's facilities to verify controls firsthand?
- On-site assessment (Correct answer)
- Desk-based assessment
- Automated scan
- Passive monitoring
Correct answer: On-site assessment
An on-site assessment allows the assessing organization to directly observe and verify the vendor's operational controls and physical security measures.
Question 6: In the CTPRP framework, what does 'residual risk' mean after vendor controls are evaluated?
- The remaining risk after accounting for the vendor's controls and mitigations (Correct answer)
- The total risk before any controls are applied
- The risk transferred to cyber insurance
- The vendor's compliance score on a SIG questionnaire
Correct answer: The remaining risk after accounting for the vendor's controls and mitigations
Residual risk is the level of risk that remains after the vendor's existing controls and mitigations have been evaluated and credited.
Which document is most commonly used as the foundation for third-party risk assessments in the US financial sector?