CTPRP Contract Management and Vendor Oversight 2 — Questions and Answers
Question 1: Which key performance indicator (KPI) is most relevant to monitoring a vendor's operational risk in an outsourced IT service?
- Vendor employee satisfaction scores
- System uptime and availability percentage against contracted SLAs (Correct answer)
- Number of vendor sales representatives assigned to the account
- Vendor's annual revenue growth rate
Correct answer: System uptime and availability percentage against contracted SLAs
System uptime and availability measured against SLA thresholds directly reflects operational risk and ensures the vendor is delivering the contractually agreed service levels.
Question 2: What is 'contract risk concentration' in third-party risk management?
- Having multiple contracts with the same legal counsel
- Over-reliance on a single vendor for a critical service, increasing exposure if that vendor fails (Correct answer)
- Concentrating all contract negotiations in one quarter
- Requiring all vendors to carry the same insurance policy
Correct answer: Over-reliance on a single vendor for a critical service, increasing exposure if that vendor fails
Contract risk concentration occurs when an organization relies heavily on one vendor for a critical service, creating a single point of failure that can be catastrophic if the vendor experiences an outage or failure.
Question 3: During ongoing vendor oversight, a 'change management' provision in a contract is designed to:
- Allow the vendor to change contract terms unilaterally during the contract period
- Require the vendor to notify and obtain approval for significant changes to personnel, systems, or processes (Correct answer)
- Enable the organization to change payment terms without vendor consent
- Mandate quarterly changes to the vendor's security protocols
Correct answer: Require the vendor to notify and obtain approval for significant changes to personnel, systems, or processes
Change management provisions require vendors to formally notify the organization and seek approval before making material changes that could affect service quality, security posture, or compliance.
Question 4: In vendor contract negotiations, an 'escrow arrangement' for software source code primarily protects the organization from:
- Intellectual property theft by the organization's employees
- The risk of losing access to critical software if the vendor goes out of business or is acquired (Correct answer)
- Regulatory fines for using unlicensed software
- The vendor raising software licensing fees after contract signing
Correct answer: The risk of losing access to critical software if the vendor goes out of business or is acquired
A source code escrow arrangement ensures that if a software vendor ceases operations or cannot support the product, the organization can access the source code to maintain or migrate the software.
Question 5: Which of the following is the BEST reason to include a 'benchmarking' clause in a long-term vendor contract?
- To allow the vendor to benchmark the organization's internal processes
- To enable the organization to periodically compare vendor pricing and performance against market standards (Correct answer)
- To require the vendor to benchmark all employees annually
- To establish a baseline for the vendor's marketing spend
Correct answer: To enable the organization to periodically compare vendor pricing and performance against market standards
A benchmarking clause allows the organization to periodically compare the vendor's pricing and service quality against market peers, ensuring ongoing value and competitiveness over the contract's life.
Question 6: What is the primary risk management benefit of establishing a formal vendor offboarding process?
- It ensures the vendor receives a positive exit review from the organization
- It ensures all access is revoked, data is returned or destroyed, and transition risks are managed in an orderly manner (Correct answer)
- It allows the vendor to retain copies of all organizational data for their records
- It simplifies the organization's accounts payable reconciliation
Correct answer: It ensures all access is revoked, data is returned or destroyed, and transition risks are managed in an orderly manner
A formal offboarding process mitigates risks associated with contract termination by ensuring all access credentials are revoked, sensitive data is handled appropriately, and transition activities are completed without gaps.
Question 7: In a third-party risk context, 'contract tiering' refers to:
- Categorizing contract types by their legal complexity
- Applying different levels of contractual requirements and oversight based on a vendor's risk classification (Correct answer)
- Requiring vendors to bid on contracts in multiple rounds
- Tiering payment milestones throughout the contract period
Correct answer: Applying different levels of contractual requirements and oversight based on a vendor's risk classification
Contract tiering aligns contractual requirements and monitoring intensity with the vendor's risk level, so high-risk critical vendors face more stringent obligations than lower-risk vendors.
Which key performance indicator (KPI) is most relevant to monitoring a vendor's operational risk in an outsourced IT service?