CTPRP Contract Management and Vendor Oversight 4 — Questions and Answers
Question 1: A vendor's contract is up for renewal, but the vendor has repeatedly missed SLA targets. What is the MOST appropriate first action before renegotiating terms?
- Terminate the contract immediately and source a new vendor
- Conduct a formal performance review and document all SLA breaches (Correct answer)
- Automatically renew with the same terms to avoid disruption
- Escalate the issue to the vendor's executive team without documentation
Correct answer: Conduct a formal performance review and document all SLA breaches
Documenting SLA breaches through a formal performance review creates an evidence-based foundation for renegotiation or termination decisions.
Question 2: Which contract clause specifically grants the organization the legal right to inspect a vendor's operational processes, financial records, and security controls?
- Indemnification clause
- Right-to-audit clause (Correct answer)
- Limitation of liability clause
- Force majeure clause
Correct answer: Right-to-audit clause
A right-to-audit clause explicitly authorizes the contracting organization to examine vendor operations, finances, and controls to verify compliance.
Question 3: A third-party vendor discloses that it has subcontracted a critical function to a fourth party without prior approval. What risk management concern does this PRIMARILY raise?
- Reputational risk from public disclosure
- Concentration risk from single-source dependency
- Nth-party risk due to lack of visibility and control (Correct answer)
- Operational risk from duplicate service provisioning
Correct answer: Nth-party risk due to lack of visibility and control
Unapproved subcontracting introduces nth-party risk because the organization has no direct contractual relationship or oversight over the fourth party.
Question 4: During contract negotiations, a vendor insists on a mutual indemnification clause. What does mutual indemnification mean for the contracting organization?
- Only the vendor is responsible for third-party claims
- Both parties agree to hold each other harmless for their respective breaches or negligence (Correct answer)
- The organization assumes full liability for all vendor actions
- Indemnification is limited to direct damages only
Correct answer: Both parties agree to hold each other harmless for their respective breaches or negligence
Mutual indemnification means each party agrees to defend and compensate the other for losses arising from its own negligence or breach, creating reciprocal protection.
Question 5: An organization's vendor management policy requires quarterly business reviews (QBRs) for Tier 1 vendors. What is the PRIMARY purpose of a QBR?
- To renegotiate contract pricing each quarter
- To assess vendor performance, discuss strategic alignment, and address emerging risks (Correct answer)
- To fulfill regulatory audit requirements
- To evaluate the vendor's financial statements only
Correct answer: To assess vendor performance, discuss strategic alignment, and address emerging risks
QBRs provide a structured forum to review performance against SLAs, align on strategic objectives, and proactively identify and mitigate emerging risks.
Question 6: A financial institution's regulator requires that all vendor contracts include provisions for business continuity and disaster recovery. Which contract element BEST satisfies this requirement?
- A confidentiality and non-disclosure agreement
- A business continuity and disaster recovery (BC/DR) addendum with tested RTO and RPO commitments (Correct answer)
- A standard limitation of liability clause
- A most-favored-nation pricing clause
Correct answer: A business continuity and disaster recovery (BC/DR) addendum with tested RTO and RPO commitments
A BC/DR addendum with specific, tested RTO and RPO commitments directly addresses regulatory requirements for operational resilience and continuity planning.
Question 7: When a vendor contract expires and the relationship is transitioning to a new provider, which activity is MOST critical from a risk management perspective?
- Immediately terminating the vendor's system access on contract end date
- Ensuring a data return, destruction, and transition assistance clause was included in the original contract (Correct answer)
- Negotiating a retroactive indemnification clause
- Assigning the contract to the new vendor without amendment
Correct answer: Ensuring a data return, destruction, and transition assistance clause was included in the original contract
Pre-negotiated data return, destruction, and transition assistance provisions ensure a controlled offboarding that protects data and maintains service continuity.
A vendor's contract is up for renewal, but the vendor has repeatedly missed SLA targets.
What is the MOST appropriate first action before renegotiating terms?