CTPRP Communication and Expression 2 — Questions and Answers
Question 1: When escalating a critical third-party risk finding to the board, which communication approach is most effective?
- Send raw assessment data without interpretation
- Translate technical findings into business impact language with quantified risk exposure (Correct answer)
- Delegate escalation entirely to the vendor relationship manager
- Wait until the annual risk report to consolidate findings
Correct answer: Translate technical findings into business impact language with quantified risk exposure
Board communications require business-impact framing with quantified risk exposure rather than technical jargon.
Question 2: A TPRM practitioner disagrees with a business unit's risk acceptance decision. What is the appropriate communication step?
- Override the business unit's decision using TPRM authority
- Document the disagreement formally and escalate through proper governance channels (Correct answer)
- Ignore the issue since risk acceptance is the business unit's prerogative
- Publicly announce the disagreement to create accountability
Correct answer: Document the disagreement formally and escalate through proper governance channels
Formal documentation and escalation through governance channels preserves objectivity and creates an audit trail.
Question 3: Which element is most critical when drafting a vendor remediation communication?
- Using technical cybersecurity terminology exclusively
- Specifying clear deadlines, required actions, and escalation consequences (Correct answer)
- Keeping the communication informal to maintain the vendor relationship
- Omitting consequences to avoid damaging the vendor relationship
Correct answer: Specifying clear deadlines, required actions, and escalation consequences
Effective remediation communications must include specific deadlines, required actions, and stated consequences for non-compliance.
Question 4: What is the primary purpose of a TPRM program communication plan?
- To restrict information flow to only senior leadership
- To ensure stakeholders receive timely, relevant risk information through defined channels (Correct answer)
- To document vendor contract terms and SLAs
- To replace the need for formal governance committee meetings
Correct answer: To ensure stakeholders receive timely, relevant risk information through defined channels
A communication plan defines who receives what information, through which channels, and at what frequency to support informed decision-making.
Question 5: During a vendor on-site assessment, the assessor discovers a significant security gap. What is the best immediate communication action?
- Complete the full assessment before communicating anything
- Verbally notify the vendor contact and document a preliminary finding immediately (Correct answer)
- Contact the vendor's regulator directly without informing the vendor
- Withhold the finding until legal counsel reviews the situation
Correct answer: Verbally notify the vendor contact and document a preliminary finding immediately
Immediate verbal notification and documentation ensures the vendor is aware and allows timely remediation discussion.
Question 6: Which reporting metric best communicates third-party risk program health to executive leadership?
- Total number of questionnaires sent to vendors
- Percentage of critical vendors with overdue remediations trending over time (Correct answer)
- Number of TPRM staff hours spent on assessments
- Total pages in vendor contracts reviewed
Correct answer: Percentage of critical vendors with overdue remediations trending over time
Trending remediation status for critical vendors directly reflects program effectiveness and outstanding risk exposure.
Question 7: A vendor refuses to share certain security documentation citing confidentiality. How should the TPRM practitioner communicate this stalemate to internal stakeholders?
- Accept the vendor's position without further communication
- Report the limitation, document residual risk, and recommend compensating controls or contract provisions (Correct answer)
- Terminate the vendor relationship immediately
- Share the vendor's confidential documents with stakeholders anyway
Correct answer: Report the limitation, document residual risk, and recommend compensating controls or contract provisions
Documenting information gaps, assessing residual risk, and recommending compensating controls ensures stakeholders can make informed decisions.
When escalating a critical third-party risk finding to the board, which communication approach is most effective?