CTPRP Regulatory Compliance and Vendor Governance 4 — Questions and Answers
Question 1: Under the OCC's third-party risk management guidance, which activity requires the MOST rigorous due diligence before engagement?
- Routine administrative vendor relationships
- Critical activities that could harm consumers if the third party fails (Correct answer)
- Technology vendors providing non-core software tools
- Office supply and facilities management vendors
Correct answer: Critical activities that could harm consumers if the third party fails
OCC guidance requires the most rigorous due diligence for third parties performing critical activities, especially those that could harm consumers or the bank if the arrangement fails.
Question 2: A financial institution discovers a vendor is subcontracting a critical function to a fourth party without notification. Which regulatory requirement does this MOST likely violate?
- Anti-money laundering (AML) provisions
- Contract provisions requiring prior approval of subcontracting arrangements (Correct answer)
- Community Reinvestment Act (CRA) obligations
- Equal Credit Opportunity Act (ECOA) requirements
Correct answer: Contract provisions requiring prior approval of subcontracting arrangements
Most regulatory frameworks require vendors to obtain prior approval before subcontracting critical functions, and contracts should contain provisions explicitly addressing fourth-party arrangements.
Question 3: Which element is MOST critical when conducting vendor due diligence for a cloud service provider handling regulated data?
- The vendor's marketing materials and client testimonials
- The vendor's SOC 2 Type II report and data residency controls (Correct answer)
- The number of years the vendor has been in business
- The vendor's physical office locations
Correct answer: The vendor's SOC 2 Type II report and data residency controls
A SOC 2 Type II report provides evidence of operational effectiveness of security controls over time, while data residency controls confirm compliance with data sovereignty regulations.
Question 4: Under GDPR, when a US company uses a European vendor to process EU personal data, the US company is classified as the:
- Data processor with full liability
- Data controller responsible for determining processing purposes (Correct answer)
- Joint controller sharing equal liability with the vendor
- Data subject with rights to erasure
Correct answer: Data controller responsible for determining processing purposes
Under GDPR, the entity that determines the purposes and means of processing personal data is the data controller, which retains ultimate responsibility for compliance.
Question 5: A vendor governance framework should include 'right to audit' clauses primarily to:
- Negotiate better pricing during contract renewals
- Verify vendor compliance with contractual and regulatory requirements (Correct answer)
- Access vendor intellectual property for competitive analysis
- Reduce the organization's own internal audit workload
Correct answer: Verify vendor compliance with contractual and regulatory requirements
Right-to-audit clauses give organizations the contractual authority to verify that vendors are meeting their compliance obligations and adhering to agreed security standards.
Question 6: Which regulatory framework specifically requires financial institutions to maintain a comprehensive inventory of critical third-party service providers?
- Sarbanes-Oxley Act (SOX) Section 404
- FFIEC IT Examination Handbook on Third-Party Risk (Correct answer)
- Health Insurance Portability and Accountability Act (HIPAA)
- Payment Card Industry Data Security Standard (PCI DSS)
Correct answer: FFIEC IT Examination Handbook on Third-Party Risk
The FFIEC IT Examination Handbook provides guidance requiring financial institutions to maintain inventories of third-party relationships, particularly those involving critical services.
Question 7: When a vendor experiences a data breach, which action should the contracting organization take FIRST according to best-practice vendor governance?
- Immediately terminate the vendor contract
- Invoke contractual breach notification requirements and assess exposure (Correct answer)
- Issue a public statement distancing from the vendor
- Transfer all vendor functions to an internal team
Correct answer: Invoke contractual breach notification requirements and assess exposure
The immediate priority is to invoke contractual breach notification provisions to understand the scope of exposure and coordinate the incident response according to established procedures.
Under the OCC's third-party risk management guidance, which activity requires the MOST rigorous due diligence before engagement?