CTPRP Evaluation Details 2 — Questions and Answers
Question 1: Which evaluation methodology best supports continuous monitoring of a third party's control environment between annual assessments?
- Full on-site audit repeated quarterly
- Automated control testing and real-time risk indicator feeds (Correct answer)
- Requiring the vendor to self-certify annually
- Replacing ongoing monitoring with a single SOC 2 report
Correct answer: Automated control testing and real-time risk indicator feeds
Automated control testing and real-time risk indicators enable continuous visibility without the cost of repeated full audits.
Question 2: A vendor's SOC 2 Type II report covers a 6-month period ending 9 months ago. What is the primary concern for a risk evaluator?
- The report uses Trust Service Criteria rather than COSO
- The coverage period is too short for meaningful assurance
- The report is stale and may not reflect current controls (Correct answer)
- SOC 2 Type II reports are not acceptable for third-party risk
Correct answer: The report is stale and may not reflect current controls
A report that is 9 months old may not capture control changes made since the coverage period, creating a gap in assurance.
Question 3: During an on-site evaluation, an assessor discovers that access control logs exist but are never reviewed. Which risk domain does this finding primarily affect?
- Strategic risk
- Compliance risk
- Information security risk (Correct answer)
- Reputational risk
Correct answer: Information security risk
Unreviewed access logs represent a detective control gap within the information security domain, leaving unauthorized access undetected.
Question 4: When evaluating a fourth-party (subcontractor of a vendor), the MOST appropriate first step is to:
- Conduct a direct on-site audit of the fourth party
- Review the vendor's own third-party risk program and subcontractor inventory (Correct answer)
- Require the fourth party to complete your standard due diligence questionnaire
- Exclude fourth parties unless they are explicitly named in the contract
Correct answer: Review the vendor's own third-party risk program and subcontractor inventory
Reviewing the vendor's own TPRM program and subcontractor inventory establishes concentration risk visibility before deciding if direct engagement is warranted.
Question 5: A risk tiering model classifies vendors as Critical, High, Medium, or Low. Which factor most directly elevates a vendor from Medium to High tier?
- The vendor is headquartered outside the United States
- The vendor has access to regulated customer data at scale (Correct answer)
- The vendor charges more than $500,000 annually
- The vendor uses open-source software components
Correct answer: The vendor has access to regulated customer data at scale
Access to regulated customer data at scale significantly increases the potential impact of a vendor incident, driving a higher risk tier.
Question 6: An evaluator receives a completed security questionnaire but cannot verify any of the vendor's responses. The BEST next step is to:
- Accept the responses at face value to maintain the vendor relationship
- Request supporting evidence such as audit reports, screenshots, or policies (Correct answer)
- Escalate immediately to the board of directors
- Terminate the vendor engagement pending a full re-evaluation
Correct answer: Request supporting evidence such as audit reports, screenshots, or policies
Requesting supporting evidence allows the evaluator to validate self-reported controls and ensure the questionnaire reflects actual practice.
Question 7: Which evaluation output is MOST useful for communicating third-party risk posture to senior management?
- Raw questionnaire response data exported to a spreadsheet
- A risk-rated heat map with aggregated vendor scores and trend data (Correct answer)
- A detailed technical findings report from each vendor assessment
- A list of all open vendor tickets in the issue tracking system
Correct answer: A risk-rated heat map with aggregated vendor scores and trend data
A heat map with aggregated scores and trends translates technical findings into executive-level insight for decision-making.
Which evaluation methodology best supports continuous monitoring of a third party's control environment between annual assessments?