CTPRP Maintenance of Credential 3 — Questions and Answers
Question 1: A CTPRP holder moves to a different industry but still performs third-party risk functions. How does this affect their renewal eligibility?
- They must surrender the credential since it is industry-specific
- They remain eligible as long as they complete the required CPE in TPRM-relevant topics (Correct answer)
- They must apply for a new credential type appropriate to their new industry
- They are exempt from CPE requirements during the transition year
Correct answer: They remain eligible as long as they complete the required CPE in TPRM-relevant topics
The CTPRP is a role-based credential, not industry-specific, so holders remain eligible for renewal as long as CPE requirements are met.
Question 2: Which type of CPE activity is most aligned with CTPRP renewal standards?
- A leadership seminar focused on executive communications
- A workshop on SIG questionnaire updates and third-party assessment practices (Correct answer)
- A general project management certification course
- An IT infrastructure bootcamp with no risk management component
Correct answer: A workshop on SIG questionnaire updates and third-party assessment practices
CPE activities directly related to third-party risk assessment tools and practices, such as SIG questionnaire updates, are most relevant to CTPRP renewal.
Question 3: What happens if a CTPRP holder is audited and cannot provide documentation for claimed CPE credits?
- The credits are automatically accepted based on the holder's attestation
- The undocumented credits may be disallowed, potentially placing the credential in non-compliance (Correct answer)
- The holder receives a 90-day extension to locate the documentation
- The credential is permanently revoked with no appeal process
Correct answer: The undocumented credits may be disallowed, potentially placing the credential in non-compliance
Inability to substantiate CPE credits during an audit can result in those credits being disallowed and the credential being placed in a non-compliant status.
Question 4: A CTPRP holder completes an online self-study course on cybersecurity vendor risk. What is the most important step to validate this as a CPE activity?
- Notify the certifying body within 30 days of completion
- Retain a certificate of completion or other evidence of the activity (Correct answer)
- Have a supervisor sign off on the learning outcomes
- Convert the hours to credits at a ratio of 2:1
Correct answer: Retain a certificate of completion or other evidence of the activity
Retaining a certificate of completion or equivalent documentation is essential to substantiate self-study CPE activities if audited.
Question 5: How does publication of a TPRM-related article or whitepaper typically affect a CTPRP holder's CPE credits?
- Publications are never accepted as CPE activities
- Publishing professional content in a relevant field generally qualifies for CPE credits (Correct answer)
- Only peer-reviewed academic journal publications qualify
- Credits are awarded only if the publication is endorsed by Shared Assessments
Correct answer: Publishing professional content in a relevant field generally qualifies for CPE credits
Publishing professional content relevant to third-party risk management is generally accepted as a CPE-qualifying activity that reflects professional contribution.
Question 6: A CTPRP holder serves on a third-party risk committee at their organization. This type of professional involvement would most likely:
- Never qualify for CPE credit as it is considered regular job duties
- Qualify for CPE credit if it involves structured learning or advancement of TPRM knowledge (Correct answer)
- Automatically generate the maximum allowable CPE credits for the cycle
- Disqualify the holder from other CPE activities in the same category
Correct answer: Qualify for CPE credit if it involves structured learning or advancement of TPRM knowledge
Committee or professional body participation qualifies for CPE credit when it involves structured advancement of relevant professional knowledge.
Question 7: Which statement about CTPRP renewal fees is most accurate?
- Renewal is free for all credential holders as part of the initial exam fee
- A renewal fee is typically required in addition to completing CPE requirements (Correct answer)
- Renewal fees are waived for holders employed by Shared Assessments member organizations
- Renewal fees are only assessed if the holder fails to meet CPE requirements on time
Correct answer: A renewal fee is typically required in addition to completing CPE requirements
CTPRP renewal requires both the completion of CPE credits and payment of a renewal fee to the certifying body.
A CTPRP holder moves to a different industry but still performs third-party risk functions.
How does this affect their renewal eligibility?