CTPRP Theory and Fundamentals 2 — Questions and Answers
Question 1: Which principle states that an organization cannot outsource its accountability for regulatory compliance to a third party?
- Delegation doctrine
- Non-delegable duty principle (Correct answer)
- Shared responsibility model
- Vicarious liability transfer
Correct answer: Non-delegable duty principle
The non-delegable duty principle holds that regulated entities remain accountable for compliance obligations even when functions are outsourced to vendors.
Question 2: In third-party risk management, what does 'inherent risk' represent?
- Risk remaining after controls are applied
- Risk before any controls or mitigations are considered (Correct answer)
- Risk transferred to the vendor via contract
- Risk identified during onboarding assessments
Correct answer: Risk before any controls or mitigations are considered
Inherent risk is the level of risk that exists in the absence of any controls, representing the raw exposure from engaging a third party.
Question 3: What is the primary purpose of a risk appetite statement in the context of TPRM?
- To define the maximum financial loss acceptable from vendor failures
- To establish thresholds guiding which third-party risks are acceptable or require mitigation (Correct answer)
- To document regulatory requirements for third-party oversight
- To outline contractual obligations vendors must meet
Correct answer: To establish thresholds guiding which third-party risks are acceptable or require mitigation
A risk appetite statement sets organizational boundaries for tolerable risk levels, guiding decisions on whether to accept, mitigate, transfer, or avoid third-party risks.
Question 4: Which type of third-party relationship typically poses the GREATEST concentration risk?
- A vendor providing non-critical administrative services to one department
- A single vendor supporting multiple critical business functions across the organization (Correct answer)
- A vendor shared with competitors in the same industry
- A vendor operating in a foreign jurisdiction with different regulations
Correct answer: A single vendor supporting multiple critical business functions across the organization
Concentration risk is highest when a single vendor supports multiple critical functions, meaning vendor failure could simultaneously disrupt numerous key operations.
Question 5: Which framework explicitly introduced the concept of 'nth-party' risk to address extended supply chain exposures?
- ISO 27001
- NIST SP 800-161 (Correct answer)
- COBIT 5
- Basel III
Correct answer: NIST SP 800-161
NIST SP 800-161 addresses supply chain risk management including nth-party risks arising from subcontractors and vendors of vendors.
Question 6: What distinguishes a 'critical' vendor from a 'strategic' vendor in TPRM classification?
- Critical vendors provide unique services; strategic vendors are interchangeable
- Critical vendors are essential to operations or compliance; strategic vendors align with long-term business goals (Correct answer)
- Strategic vendors have higher spend; critical vendors have lower contract value
- Critical vendors are domestic; strategic vendors are international
Correct answer: Critical vendors are essential to operations or compliance; strategic vendors align with long-term business goals
Critical vendors are those whose failure would significantly disrupt operations or violate regulatory requirements, while strategic vendors are valued for long-term business alignment.
Question 7: In the TPRM lifecycle, what is the correct sequence of the initial phases?
- Assessment → Selection → Onboarding → Monitoring
- Planning → Identification → Assessment → Selection
- Identification → Due diligence → Contracting → Onboarding (Correct answer)
- Onboarding → Risk assessment → Contracting → Monitoring
Correct answer: Identification → Due diligence → Contracting → Onboarding
The standard TPRM lifecycle begins with identifying the need, conducting due diligence, formalizing the relationship through contracting, and then onboarding the vendor.
Which principle states that an organization cannot outsource its accountability for regulatory compliance to a third party?