CTPRP Credential Requirements 2 — Questions and Answers
Question 1: How many hours of continuing professional education (CPE) must a CTPRP holder complete annually to maintain the credential?
- 10 hours
- 15 hours (Correct answer)
- 20 hours
- 25 hours
Correct answer: 15 hours
CTPRP holders must complete 15 CPE hours annually to maintain their certification.
Question 2: Which organization administers the CTPRP certification examination?
- ISACA
- Shared Assessments (Correct answer)
- IAPP
- RIMS
Correct answer: Shared Assessments
The CTPRP is administered by Shared Assessments, the leading organization focused on third-party risk management.
Question 3: What is the primary purpose of the CTPRP designation for a professional's career?
- Qualifies the holder to conduct financial audits
- Demonstrates proficiency in third-party risk management practices (Correct answer)
- Certifies expertise in cybersecurity penetration testing
- Validates knowledge of international trade compliance
Correct answer: Demonstrates proficiency in third-party risk management practices
The CTPRP designation validates a professional's competency in managing third-party vendor risks.
Question 4: Which of the following best describes an acceptable CPE activity for CTPRP renewal?
- Completing unrelated IT certifications
- Attending a vendor risk management webinar (Correct answer)
- Reading personal finance blogs
- Volunteering at a community event
Correct answer: Attending a vendor risk management webinar
CPE activities must be directly relevant to third-party risk management topics to count toward CTPRP renewal.
Question 5: If a CTPRP holder fails to meet the annual CPE requirement, what is the most likely consequence?
- A written warning is issued with no other penalty
- The certification may be suspended or revoked (Correct answer)
- The holder is automatically downgraded to an associate level
- No consequence occurs until the three-year renewal cycle ends
Correct answer: The certification may be suspended or revoked
Failure to meet annual CPE requirements can result in suspension or revocation of the CTPRP credential.
Question 6: Which domain is NOT typically covered by the CTPRP body of knowledge?
- Third-party risk program governance
- Vendor due diligence and oversight
- Personal investment portfolio management (Correct answer)
- Information security and privacy controls for vendors
Correct answer: Personal investment portfolio management
Personal investment management is not relevant to third-party risk and is outside the CTPRP body of knowledge.
Question 7: What is the recommended professional background for candidates seeking the CTPRP certification?
- At least five years in retail banking
- Experience in vendor/third-party risk management, audit, or compliance roles (Correct answer)
- A doctoral degree in information technology
- Two years of software development experience
Correct answer: Experience in vendor/third-party risk management, audit, or compliance roles
Candidates with backgrounds in vendor management, audit, or compliance are the target audience for the CTPRP.
How many hours of continuing professional education (CPE) must a CTPRP holder complete annually to maintain the credential?