CTPRP Regulatory Compliance and Vendor Governance 5 — Questions and Answers
Question 1: Which of the following BEST describes 'concentration risk' in third-party risk management?
- The risk that a single vendor error causes a minor service disruption
- Over-reliance on a limited number of vendors for critical functions, creating systemic vulnerability (Correct answer)
- The financial cost of maintaining multiple vendor contracts simultaneously
- Regulatory penalties for using international vendors
Correct answer: Over-reliance on a limited number of vendors for critical functions, creating systemic vulnerability
Concentration risk refers to the systemic vulnerability created when an organization over-relies on a single or few vendors for critical functions, meaning one failure affects multiple operations.
Question 2: Under NY DFS Cybersecurity Regulation (23 NYCRR 500), what is required regarding third-party service providers?
- All vendors must be certified by NY DFS directly
- Covered entities must implement written policies governing third-party cybersecurity practices (Correct answer)
- Vendors must maintain their own NY DFS licenses
- Third-party contracts must not exceed five years in duration
Correct answer: Covered entities must implement written policies governing third-party cybersecurity practices
23 NYCRR 500 requires covered entities to implement written policies and procedures designed to ensure the security of information systems accessible to third-party service providers.
Question 3: A vendor's Business Continuity Plan (BCP) should be reviewed by the contracting organization primarily to:
- Verify the vendor's financial solvency and credit rating
- Ensure the vendor can maintain services during disruptions in alignment with the organization's RTO/RPO (Correct answer)
- Confirm the vendor has adequate office space for staff
- Evaluate the vendor's employee benefits and retention programs
Correct answer: Ensure the vendor can maintain services during disruptions in alignment with the organization's RTO/RPO
Reviewing a vendor's BCP ensures their recovery time objectives (RTO) and recovery point objectives (RPO) are compatible with the contracting organization's own continuity requirements.
Question 4: Which scenario represents the MOST significant vendor governance failure?
- A vendor submits an annual compliance certification two weeks late
- A vendor accesses production systems beyond agreed scope without authorization (Correct answer)
- A vendor requests a contract amendment to adjust service pricing
- A vendor transitions account managers without advance notice
Correct answer: A vendor accesses production systems beyond agreed scope without authorization
Unauthorized access to production systems beyond the agreed scope represents a critical security and compliance failure that could trigger regulatory violations and data breach liability.
Question 5: In the context of TPRM, 'inherent risk' is BEST defined as:
- The residual risk remaining after all controls are applied
- The risk exposure before any mitigating controls are considered (Correct answer)
- The financial cost of managing vendor relationships
- Regulatory penalties already assessed against a vendor
Correct answer: The risk exposure before any mitigating controls are considered
Inherent risk represents the level of risk that exists in a vendor relationship based on factors like data access, criticality, and geography before any controls or mitigations are applied.
Question 6: Which practice BEST ensures ongoing vendor compliance throughout the contract lifecycle rather than only at onboarding?
- Conducting a single comprehensive audit at contract inception
- Implementing continuous monitoring with periodic reassessments tied to risk tier (Correct answer)
- Requiring vendors to self-certify compliance on an annual basis only
- Relying on public regulatory filings to track vendor compliance status
Correct answer: Implementing continuous monitoring with periodic reassessments tied to risk tier
Continuous monitoring combined with periodic reassessments based on risk tier ensures that changing risk profiles, new regulatory requirements, and emerging issues are identified throughout the relationship.
Question 7: When regulators examine a financial institution's third-party risk management program, which deficiency is MOST likely to result in a Matters Requiring Attention (MRA)?
- Minor delays in vendor invoice processing
- Lack of a documented exit strategy for critical vendor relationships (Correct answer)
- Using standardized rather than customized vendor questionnaires
- Reviewing vendor contracts on a three-year rather than annual cycle
Correct answer: Lack of a documented exit strategy for critical vendor relationships
Regulators specifically look for documented exit strategies for critical vendors, as the absence of a transition plan represents a material gap that could leave the institution unable to maintain services if a vendor fails.
Which of the following BEST describes 'concentration risk' in third-party risk management?