CTPRP Repertoire and Literature 2 — Questions and Answers
Question 1: Which regulatory guidance document issued by the OCC specifically addresses risk management expectations for bank relationships with third parties?
- OCC Bulletin 2013-29 (Correct answer)
- OCC Bulletin 2011-12
- OCC Circular 2006-39
- OCC Bulletin 2017-21
Correct answer: OCC Bulletin 2013-29
OCC Bulletin 2013-29 provides comprehensive guidance on third-party risk management expectations for national banks and federal savings associations.
Question 2: The NIST Cybersecurity Framework (CSF) core functions most relevant to third-party risk management include all of the following EXCEPT:
- Identify
- Protect
- Innovate (Correct answer)
- Respond
Correct answer: Innovate
The NIST CSF five core functions are Identify, Protect, Detect, Respond, and Recover; 'Innovate' is not one of them.
Question 3: ISO/IEC 27036 is the international standard series specifically focused on:
- Information security for supplier relationships (Correct answer)
- Business continuity management
- Privacy information management
- Cloud service security
Correct answer: Information security for supplier relationships
ISO/IEC 27036 provides guidance on information security for supplier relationships, making it directly relevant to TPRM practitioners.
Question 4: The Shared Assessments Program's Standardized Information Gathering (SIG) questionnaire is primarily used for:
- Assessing third-party cybersecurity and operational risk controls (Correct answer)
- Scoring vendor financial stability
- Benchmarking SLA performance metrics
- Evaluating fourth-party concentration risk
Correct answer: Assessing third-party cybersecurity and operational risk controls
The SIG questionnaire is a standardized tool designed to assess a vendor's information security, privacy, and operational risk controls.
Question 5: Under the FFIEC IT Examination Handbook on Outsourcing Technology Services, which phase of the vendor management lifecycle requires the most rigorous oversight activities?
- Ongoing monitoring and management (Correct answer)
- Initial due diligence
- Contract negotiation
- Vendor selection
Correct answer: Ongoing monitoring and management
The FFIEC handbook emphasizes that ongoing monitoring is critical to ensure third parties continue to meet contractual and regulatory obligations throughout the relationship.
Question 6: Which framework published by ISACA provides guidance specifically on governance and management of enterprise IT, including third-party arrangements?
- COBIT (Correct answer)
- COSO ERM
- NIST SP 800-53
- ISO 31000
Correct answer: COBIT
COBIT, developed by ISACA, is a framework for IT governance and management that addresses enterprise-wide IT including third-party and outsourced services.
Question 7: The COSO Enterprise Risk Management framework updated in 2017 introduced which key enhancement relevant to third-party risk?
- Integration of strategy and performance into ERM (Correct answer)
- Mandatory fourth-party assessments
- Standardized vendor scoring rubrics
- Quarterly board reporting requirements
Correct answer: Integration of strategy and performance into ERM
The 2017 COSO ERM update integrated strategy and performance considerations, recognizing that risk (including third-party risk) must align with organizational strategy.
Which regulatory guidance document issued by the OCC specifically addresses risk management expectations for bank relationships with third parties?