CTPRP Professional Practice 2 — Questions and Answers
Question 1: Which document formally defines the responsibilities, expectations, and performance metrics agreed upon between an organization and its third party?
- Non-Disclosure Agreement (NDA)
- Service Level Agreement (SLA) (Correct answer)
- Master Service Agreement (MSA)
- Statement of Work (SOW)
Correct answer: Service Level Agreement (SLA)
An SLA specifically captures measurable performance targets and accountability provisions between the organization and the third party.
Question 2: A CTPRP practitioner discovers a vendor has subcontracted critical processing to a fourth party without prior disclosure. What is the MOST appropriate immediate action?
- Terminate the vendor contract immediately
- Notify the vendor and escalate per the incident response plan (Correct answer)
- Accept the arrangement if the fourth party has good ratings
- Update the risk register and take no further action
Correct answer: Notify the vendor and escalate per the incident response plan
Undisclosed subcontracting is a contract breach and potential risk event requiring escalation through the established incident response process.
Question 3: What is the primary purpose of a vendor tiering model in third-party risk management?
- To rank vendors by revenue contribution
- To prioritize due diligence and monitoring intensity based on risk exposure (Correct answer)
- To negotiate better pricing with high-volume vendors
- To determine vendor payment schedules
Correct answer: To prioritize due diligence and monitoring intensity based on risk exposure
Tiering allows organizations to allocate limited resources by applying the most rigorous controls to vendors that pose the greatest risk.
Question 4: Which phase of the third-party risk lifecycle involves assessing whether a prospective vendor's risk profile is acceptable before contracting?
- Ongoing monitoring
- Offboarding
- Pre-contract due diligence (Correct answer)
- Contract remediation
Correct answer: Pre-contract due diligence
Pre-contract due diligence evaluates inherent and residual risk before the organization commits to a vendor relationship.
Question 5: Under US regulatory guidance, which type of vendor relationship typically triggers the HIGHEST level of regulatory scrutiny?
- Vendors providing office supplies
- Critical service providers that perform functions material to the institution (Correct answer)
- Vendors in low-risk geographic regions
- Vendors with ISO 27001 certification
Correct answer: Critical service providers that perform functions material to the institution
Regulators such as OCC and FFIEC require heightened oversight for vendors performing functions that could significantly impact operations, customers, or compliance.
Question 6: A TPRM program identifies that a vendor's SOC 2 Type II report has a qualified opinion. What should the risk practitioner do FIRST?
- Immediately terminate the vendor relationship
- Review the exceptions noted and assess their impact on the organization's risk posture (Correct answer)
- Accept the report without further review since SOC 2 is sufficient
- Request a new report from a different auditor
Correct answer: Review the exceptions noted and assess their impact on the organization's risk posture
A qualified opinion indicates specific control failures, and the practitioner must evaluate whether those exceptions create unacceptable risk for the organization.
Question 7: Which of the following BEST describes 'residual risk' in the context of third-party risk management?
- The total risk before any controls are applied
- The risk remaining after controls and mitigations have been implemented (Correct answer)
- The risk transferred to the vendor via contract
- The risk identified during the offboarding process
Correct answer: The risk remaining after controls and mitigations have been implemented
Residual risk is what remains after the organization has applied controls, contractual protections, and other mitigating measures.
Which document formally defines the responsibilities, expectations, and performance metrics agreed upon between an organization and its third party?