CTPRP Third-Party Risk Assessment and Due Diligence 4 — Questions and Answers
Question 1: A financial institution is onboarding a cloud-based payroll processor that will access employee PII. Which due diligence artifact is MOST critical to obtain before contract execution?
- Vendor's marketing collateral and case studies
- SOC 2 Type II report covering the prior 12-month period (Correct answer)
- Vendor's LinkedIn page and executive bios
- A verbal assurance from the sales team about security controls
Correct answer: SOC 2 Type II report covering the prior 12-month period
A SOC 2 Type II report provides independent, audited evidence of operational effectiveness of security controls over a meaningful period, directly relevant to PII handling.
Question 2: During inherent risk tiering, which combination of factors most commonly elevates a vendor to 'Critical' tier?
- Low data sensitivity and moderate access to internal systems
- High data sensitivity, deep system integration, and no viable substitutes (Correct answer)
- Moderate revenue dependency and a long contract term
- Geographic distance and time-zone differences
Correct answer: High data sensitivity, deep system integration, and no viable substitutes
Critical tier designation typically results from the convergence of sensitive data exposure, deep technical integration, and concentration risk from lack of substitutes.
Question 3: An organization discovers mid-assessment that a Tier 1 vendor subcontracts 60% of its core service delivery to an unnamed fourth party. What is the BEST immediate response?
- Accept the vendor's assurance that fourth parties are managed appropriately
- Terminate the relationship immediately without further investigation
- Require disclosure of fourth-party identities and extend due diligence to cover material subcontractors (Correct answer)
- Reduce the vendor's risk tier to Tier 2 since the work is distributed
Correct answer: Require disclosure of fourth-party identities and extend due diligence to cover material subcontractors
Material fourth-party exposure must be identified and assessed; requiring disclosure and extending due diligence preserves visibility into the full risk chain.
Question 4: Which assessment methodology is specifically designed to evaluate a third party's resilience and ability to continue services during a major disruption?
- Financial health scorecard
- Business continuity and disaster recovery (BC/DR) assessment (Correct answer)
- Anti-bribery and anti-corruption questionnaire
- Environmental, social, and governance (ESG) audit
Correct answer: Business continuity and disaster recovery (BC/DR) assessment
BC/DR assessments test whether a vendor has tested recovery plans, defined RTOs/RPOs, and can sustain service delivery through outages or disasters.
Question 5: A procurement team bypasses the TPRM process to onboard a SaaS tool quickly, citing a 'low-cost' exemption. This scenario BEST illustrates which risk?
- Market risk from competitive pricing
- Shadow IT or maverick procurement risk (Correct answer)
- Credit risk from a new vendor relationship
- Reputational risk from vendor advertising claims
Correct answer: Shadow IT or maverick procurement risk
Shadow IT or maverick procurement occurs when business units engage vendors outside established risk controls, creating unvetted exposure.
Question 6: When scoring vendor questionnaire responses, an organization uses a weighted scoring model. Which weighting approach is MOST defensible to regulators?
- Weighting all questions equally regardless of control domain
- Assigning higher weights to controls that directly mitigate the highest inherent risks for that vendor's risk tier (Correct answer)
- Weighting based solely on questionnaire question length
- Allowing vendors to self-select which questions carry the most weight
Correct answer: Assigning higher weights to controls that directly mitigate the highest inherent risks for that vendor's risk tier
Risk-aligned weighting ensures that controls most critical to mitigating a vendor's specific inherent risk profile receive proportionate scoring influence.
Question 7: A due diligence review reveals that a key IT vendor's most recent penetration test is 28 months old. According to common TPRM best practices, what is the appropriate action?
- Accept the outdated test since the environment hasn't changed visibly
- Flag as a finding and require an updated penetration test before or shortly after contract renewal (Correct answer)
- Immediately place the vendor on termination notice
- Request only a vulnerability scan as a sufficient substitute
Correct answer: Flag as a finding and require an updated penetration test before or shortly after contract renewal
Industry standards and most regulatory guidance expect penetration tests annually or biennially; a 28-month-old test should be flagged and remediation required within a defined timeframe.
A financial institution is onboarding a cloud-based payroll processor that will access employee PII.
Which due diligence artifact is MOST critical to obtain before contract execution?