CTPRP Professional Practice 3 — Questions and Answers
Question 1: Which governance structure component ensures that third-party risk management aligns with the organization's overall enterprise risk appetite?
- Vendor scorecard
- Risk appetite statement (Correct answer)
- Third-party inventory spreadsheet
- Audit trail log
Correct answer: Risk appetite statement
The risk appetite statement sets the boundaries within which TPRM decisions must operate, ensuring alignment with organizational strategy.
Question 2: An organization is offboarding a vendor that had access to sensitive customer data. Which action is MOST critical during offboarding?
- Conducting a final invoice reconciliation
- Confirming data destruction or return and revoking all access credentials (Correct answer)
- Updating the vendor's tier classification
- Requesting a final SOC 2 report
Correct answer: Confirming data destruction or return and revoking all access credentials
Data disposition and access revocation are the highest-priority security tasks during vendor offboarding to prevent unauthorized data retention or access.
Question 3: What distinguishes a 'critical' vendor from an 'important' vendor in most TPRM frameworks?
- Critical vendors have larger contracts
- Critical vendors perform functions whose failure would significantly disrupt operations or harm customers (Correct answer)
- Critical vendors are always located offshore
- Critical vendors are subject to fewer audits
Correct answer: Critical vendors perform functions whose failure would significantly disrupt operations or harm customers
Criticality is defined by the impact of failure, not by contract size or geography, and triggers stricter oversight requirements.
Question 4: Which regulatory body issued the 2023 guidance 'Third-Party Relationships: Risk Management' applicable to US national banks and federal savings associations?
- SEC
- OCC (Correct answer)
- CISA
- PCAOB
Correct answer: OCC
The OCC's 2023 interagency guidance on third-party relationships provides the risk management framework for national banks and federal savings associations.
Question 5: When evaluating a vendor's financial health during due diligence, which indicator raises the MOST immediate concern?
- Moderate revenue growth
- Going concern opinion from the external auditor (Correct answer)
- Accounts receivable aging over 60 days
- Slight decrease in profit margin year-over-year
Correct answer: Going concern opinion from the external auditor
A going concern opinion indicates the auditor doubts the vendor's ability to continue operations, representing a critical continuity risk.
Question 6: A TPRM practitioner is building a vendor inventory. Which data element is MOST essential to capture for every third party?
- Vendor CEO's LinkedIn profile
- Type and criticality of services provided and data accessed (Correct answer)
- Vendor's marketing budget
- Number of vendor employees
Correct answer: Type and criticality of services provided and data accessed
Services provided and data accessed directly determine the vendor's risk classification, due diligence requirements, and monitoring frequency.
Question 7: In a RACI matrix for TPRM, what does the 'A' (Accountable) designation indicate?
- The person who performs the task
- The single owner who is ultimately answerable for the outcome (Correct answer)
- Everyone who must be notified when the task is complete
- Those who provide input but do not perform the task
Correct answer: The single owner who is ultimately answerable for the outcome
The Accountable role is the single point of ultimate ownership and decision-making authority for an activity or deliverable.
Which governance structure component ensures that third-party risk management aligns with the organization's overall enterprise risk appetite?