CTPRP Contract Management and Vendor Oversight 5 β Questions and Answers
Question 1: A vendor refuses to allow a direct on-site audit citing proprietary business concerns. What is an acceptable ALTERNATIVE oversight mechanism that many contracts permit?
- Waiving the audit requirement entirely for this vendor
- Accepting a third-party audit report such as a SOC 2 Type II in lieu of a direct audit (Correct answer)
- Requiring the vendor to self-certify compliance without any external validation
- Terminating the relationship based solely on the refusal
Correct answer: Accepting a third-party audit report such as a SOC 2 Type II in lieu of a direct audit
SOC 2 Type II and similar independent third-party audit reports are widely accepted substitutes that provide credible assurance without requiring direct access.
Question 2: What is the purpose of including a 'step-in rights' clause in a vendor contract?
- It allows the vendor to expand its service scope without approval
- It grants the organization the right to assume direct control of vendor operations if the vendor fails to perform (Correct answer)
- It requires the vendor to step in and cover the organization's internal operations
- It limits the vendor's right to subcontract critical functions
Correct answer: It grants the organization the right to assume direct control of vendor operations if the vendor fails to perform
Step-in rights allow the contracting organization to take over or redirect the vendor's operations during a service failure, protecting business continuity.
Question 3: An organization is building a vendor contract template. Which element is MOST important to include to address data privacy compliance under US state privacy laws such as CCPA?
- A most-favored-nation pricing clause
- A data processing addendum (DPA) defining roles, processing purposes, and data subject rights obligations (Correct answer)
- A non-compete clause restricting the vendor from serving competitors
- A governing law clause defaulting to the vendor's home state
Correct answer: A data processing addendum (DPA) defining roles, processing purposes, and data subject rights obligations
A DPA establishes the legal framework for data processing, aligning with CCPA and similar regulations by defining controller/processor roles and obligations.
Question 4: A contract manager notices that a vendor's insurance certificate on file has expired. What is the IMMEDIATE risk concern?
- The vendor may no longer meet minimum financial stability thresholds
- The organization may have no recourse for losses caused by an uninsured vendor incident (Correct answer)
- The vendor is likely also in breach of all SLA commitments
- Regulatory penalties will automatically be assessed against the organization
Correct answer: The organization may have no recourse for losses caused by an uninsured vendor incident
An expired insurance certificate leaves the organization exposed to unrecoverable losses if the vendor causes a covered incident during the lapse period.
Question 5: In vendor oversight, what does 'evergreen contract' risk refer to?
- Contracts that automatically renew without a periodic risk reassessment or renegotiation (Correct answer)
- Contracts with pricing tied to inflation indexes
- Long-term contracts that include green technology requirements
- Contracts that cannot be terminated for convenience
Correct answer: Contracts that automatically renew without a periodic risk reassessment or renegotiation
Evergreen contracts auto-renew, creating risk that outdated terms, unreviewed performance, or changed risk profiles persist without deliberate management oversight.
Question 6: A vendor contract includes a limitation of liability clause capping damages at one year's contract fees. During an incident, actual damages total five times the annual fee. What is the MOST significant implication for the organization?
- The organization can sue for the full amount regardless of the contract cap
- The organization can only recover up to the capped amount, leaving it exposed to the remaining loss (Correct answer)
- The limitation of liability clause is automatically unenforceable in cases of gross negligence
- The vendor must provide additional insurance to cover the gap
Correct answer: The organization can only recover up to the capped amount, leaving it exposed to the remaining loss
Contractual liability caps are generally enforceable, meaning the organization bears any losses exceeding the cap unless specific carve-outs for gross negligence or willful misconduct apply.
Question 7: Which of the following BEST describes a 'material breach' provision in a third-party contract and its relevance to vendor risk management?
- A clause that limits the vendor's ability to change subcontractors
- A defined threshold of non-performance or violation that triggers the right to terminate the contract without penalty (Correct answer)
- A pricing adjustment mechanism tied to commodity costs
- A requirement that disputes go to mediation before litigation
Correct answer: A defined threshold of non-performance or violation that triggers the right to terminate the contract without penalty
A material breach provision defines what constitutes a fundamental contract violation, giving the organization a clear, legally defensible right to terminate and seek remedies.
A vendor refuses to allow a direct on-site audit citing proprietary business concerns.
What is an acceptable ALTERNATIVE oversight mechanism that many contracts permit?