CTPRP Third-Party Risk Assessment and Due Diligence 5 — Questions and Answers
Question 1: An organization is assessing a legal services vendor that handles confidential litigation documents. Which due diligence domain is MOST uniquely important for this vendor type compared to a standard IT vendor?
- Network intrusion detection capabilities
- Attorney-client privilege, confidentiality obligations, and bar compliance (Correct answer)
- Software development lifecycle (SDLC) security practices
- Cloud infrastructure redundancy metrics
Correct answer: Attorney-client privilege, confidentiality obligations, and bar compliance
Legal vendors introduce privilege and professional ethics dimensions — confidentiality obligations under bar rules and privilege waiver risk — that are not standard IT control concerns.
Question 2: Which metric is MOST useful for evaluating the effectiveness of an organization's third-party due diligence program over time?
- Total number of vendors in the portfolio
- Percentage of Tier 1 vendors with completed, current assessments within the defined reassessment cycle (Correct answer)
- Average contract length across all vendor relationships
- Number of questionnaires sent per quarter
Correct answer: Percentage of Tier 1 vendors with completed, current assessments within the defined reassessment cycle
Assessment coverage rate for critical vendors directly measures whether the program is maintaining current risk visibility where it matters most.
Question 3: A vendor's SOC 2 Type II report contains several 'exceptions noted' within the change management control area. What is the MOST appropriate risk management response?
- Reject the vendor automatically due to any exceptions
- Request a management letter and compensating controls documentation, then assess residual risk before proceeding (Correct answer)
- Ignore exceptions if the vendor is otherwise commercially favorable
- Require the vendor to switch auditors immediately
Correct answer: Request a management letter and compensating controls documentation, then assess residual risk before proceeding
Exceptions require further investigation through management responses and compensating controls; a risk-based decision can then be made rather than automatic rejection.
Question 4: Under the OCC's Third-Party Risk Management guidance, which phase of the vendor lifecycle is explicitly called out as requiring board or senior management oversight for critical activities?
- Initial vendor prospecting and RFP drafting
- Planning, due diligence, contract negotiation, ongoing monitoring, and termination — all phases for critical activities (Correct answer)
- Only the termination phase to ensure data return
- Only the onboarding phase for initial risk acceptance
Correct answer: Planning, due diligence, contract negotiation, ongoing monitoring, and termination — all phases for critical activities
The OCC guidance states that board and senior management oversight should span all phases of the third-party relationship lifecycle for critical activities, not just a single phase.
Question 5: An assessor is evaluating a vendor's information security program and finds the vendor holds ISO 27001 certification. What is the LIMITATION of relying solely on this certification for due diligence?
- ISO 27001 is not internationally recognized and lacks credibility
- Certification confirms a management system is in place but does not guarantee absence of specific control gaps or current threat effectiveness (Correct answer)
- ISO 27001 only applies to physical security controls
- Certification automatically satisfies all regulatory third-party requirements
Correct answer: Certification confirms a management system is in place but does not guarantee absence of specific control gaps or current threat effectiveness
ISO 27001 certifies that an ISMS framework exists and meets the standard's requirements at a point in time, but does not provide detailed control-level testing results or guarantee real-world effectiveness.
Question 6: When conducting financial due diligence on a critical vendor, which indicator is the STRONGEST early-warning signal of vendor viability risk?
- The vendor recently hired a new CFO
- Consecutive years of negative operating cash flow combined with high debt-to-equity ratio and declining revenue (Correct answer)
- The vendor operates in multiple geographic markets
- The vendor's fiscal year ends in December rather than March
Correct answer: Consecutive years of negative operating cash flow combined with high debt-to-equity ratio and declining revenue
Persistent negative operating cash flow, high leverage, and revenue decline together signal liquidity stress and elevated probability of business disruption or failure.
Question 7: A TPRM analyst is asked to assess a vendor that provides services to only one business unit but stores regulated health data (PHI). How should this vendor be tiered?
- Low tier, because only one internal business unit uses the vendor
- Based on data sensitivity and regulatory exposure — PHI handling likely warrants Critical or High tier regardless of internal usage breadth (Correct answer)
- Medium tier by default since the relationship is limited in scope
- The vendor should be excluded from TPRM since it serves a single business unit
Correct answer: Based on data sensitivity and regulatory exposure — PHI handling likely warrants Critical or High tier regardless of internal usage breadth
Inherent risk tier must reflect regulatory and data sensitivity exposure, not merely the number of internal stakeholders; PHI triggers HIPAA obligations regardless of scope.
An organization is assessing a legal services vendor that handles confidential litigation documents.
Which due diligence domain is MOST uniquely important for this vendor type compared to a standard IT vendor?