CTPRP (Certified Third-Party Risk Professional) Exam β Questions and Answers
Question 1: Which regulatory framework specifically requires financial institutions to maintain a comprehensive inventory of critical third-party service providers?
- Health Insurance Portability and Accountability Act (HIPAA)
- FFIEC IT Examination Handbook on Third-Party Risk (Correct answer)
- Sarbanes-Oxley Act (SOX) Section 404
- Payment Card Industry Data Security Standard (PCI DSS)
Correct answer: FFIEC IT Examination Handbook on Third-Party Risk
The FFIEC IT Examination Handbook provides guidance requiring financial institutions to maintain inventories of third-party relationships, particularly those involving critical services.
Question 2: How does CTPRP certification benefit employers?
- It provides assurance of employee competence and commitment to professional standards (Correct answer)
- It reduces salary requirements
- It eliminates the need for on-the-job training
- It guarantees perfect job performance
Correct answer: It provides assurance of employee competence and commitment to professional standards
Certified employees have demonstrated verified knowledge and dedication to their profession, reducing risk for employers.
Question 3: Under FFIEC guidance, what must banks document as part of ongoing third-party relationship management?
- The vendor's quarterly advertising spend
- Performance reviews, risk reassessments, and any material changes to the vendor relationship (Correct answer)
- The vendor's office lease agreements
- The vendor's employee benefits packages
Correct answer: Performance reviews, risk reassessments, and any material changes to the vendor relationship
FFIEC guidance requires banks to document ongoing vendor performance, periodic risk reassessments, and any changes that could affect the risk profile of the third-party relationship.
Question 4: Which of the following is a valid reason for Shared Assessments to revoke a CTPRP credential?
- The holder changes employers
- The holder earns an additional certification
- The holder violates the CTPRP Code of Ethics (Correct answer)
- The holder transitions to a different industry
Correct answer: The holder violates the CTPRP Code of Ethics
Violations of the CTPRP Code of Ethics can result in revocation of the certification by Shared Assessments.
Question 5: Under GDPR, when a US company uses a European vendor to process EU personal data, the US company is classified as the:
- Joint controller sharing equal liability with the vendor
- Data processor with full liability
- Data controller responsible for determining processing purposes (Correct answer)
- Data subject with rights to erasure
Correct answer: Data controller responsible for determining processing purposes
Under GDPR, the entity that determines the purposes and means of processing personal data is the data controller, which retains ultimate responsibility for compliance.
Question 6: Why is understanding theory important for practical application?
- It provides the foundation for informed decision-making and creative expression (Correct answer)
- Theory is purely academic with no practical value
- Theory is only important for teaching others
- It replaces the need for practical experience
Correct answer: It provides the foundation for informed decision-making and creative expression
Theoretical understanding enables practitioners to make informed choices, solve problems, and innovate in their field.
Question 7: In the context of CTPRP credential maintenance, what counts as a 'reporting period' for CPE hours?
- An annual calendar or certification year cycle (Correct answer)
- A single 90-day quarter
- A two-year biennial period
- A 5-year rolling window
Correct answer: An annual calendar or certification year cycle
CTPRP CPE requirements are tracked on an annual basis aligned to the certification year.
Question 8: What happens if CPTRP certification renewal requirements are not met?
- Certification becomes inactive. (Correct answer)
- The professional must retake the original exam.
- Certification is permanently revoked.
- Professionals are fined for non-compliance.
Correct answer: Certification becomes inactive.
If a CTPRP certification holder fails to meet the specified renewal requirements, their certification typically transitions to an inactive status. This means they are no longer recognized as actively certified, which can impact their professional standing and ability to claim the credential. While not permanently revoked immediately, it requires specific actions to reinstate.
Question 9: The Financial Stability Board (FSB) publication 'Regulatory and Supervisory Issues Relating to Outsourcing and Third-Party Relationships' (2023) emphasizes which emerging risk topic?
- Mandatory real-time data sharing between financial institutions
- Standardized global pricing for cloud services
- Concentration risk from reliance on a small number of critical third-party providers (Correct answer)
- Elimination of offshore outsourcing for regulated firms
Correct answer: Concentration risk from reliance on a small number of critical third-party providers
The 2023 FSB paper highlights systemic concentration risk as a key concern when many regulated firms rely on the same small set of critical service providers such as cloud hyperscalers.
Question 10: What should be done when a conflict exists between different applicable standards?
- Create a new personal standard
- Ignore all conflicting standards
- Follow the least restrictive standard
- Identify the most stringent requirement and consult with relevant authorities (Correct answer)
Correct answer: Identify the most stringent requirement and consult with relevant authorities
When standards conflict, the most protective or stringent requirement typically takes precedence, with consultation as needed.
Question 11: The Shared Assessments Standardized Control Assessment (SCA) procedure is designed to be used in conjunction with the SIG to:
- Provide on-site testing procedures that validate vendor responses to the SIG questionnaire (Correct answer)
- Replace contractual audit rights for lower-tier vendors
- Automate vendor scoring using AI-based analysis of questionnaire data
- Generate mandatory regulatory reports for banking supervisors
Correct answer: Provide on-site testing procedures that validate vendor responses to the SIG questionnaire
The SCA provides standardized on-site or remote testing procedures that practitioners use to validate and verify vendor responses provided in the SIG questionnaire.
Question 12: A CTPRP holder changes their name after marriage. What is the appropriate action regarding the credential?
- Continue using the old name on credential-related materials indefinitely
- Notify the certifying body and update the name on record (Correct answer)
- Reapply for the credential under the new name
- The credential becomes invalid until a new examination is passed
Correct answer: Notify the certifying body and update the name on record
Credential holders should promptly notify the certifying body of name changes to ensure records remain accurate and the credential valid.
Question 13: Which US regulatory framework requires organizations to report material cybersecurity incidents involving third parties to the SEC within four business days?
- FFIEC IT Examination Handbook
- NIST SP 800-53
- SEC Cybersecurity Disclosure Rules (2023) (Correct answer)
- HIPAA Breach Notification Rule
Correct answer: SEC Cybersecurity Disclosure Rules (2023)
The SEC's 2023 Cybersecurity Disclosure Rules require public companies to disclose material cybersecurity incidents, including those originating from third parties, within four business days.
Question 14: How did the SolarWinds supply chain attack of 2020 reshape the historical understanding of third-party risk?
- It showed that only government contractors faced supply chain threats
- It demonstrated that trusted software update mechanisms could be weaponized to compromise thousands of organizations simultaneously (Correct answer)
- It proved that on-premises software was safer than cloud solutions
- It led immediately to mandatory TPRM regulations for all US companies
Correct answer: It demonstrated that trusted software update mechanisms could be weaponized to compromise thousands of organizations simultaneously
SolarWinds revealed that attackers could compromise a widely trusted software vendor's build process and distribute malware through legitimate update channels, affecting thousands of downstream customers including government agencies.
Question 15: Why is adherence to technical standards important in CTPRP practice?
- It limits innovation and creativity
- It is required only for government contracts
- It is only important for documentation purposes
- It ensures consistency, safety, and interoperability across the industry (Correct answer)
Correct answer: It ensures consistency, safety, and interoperability across the industry
Technical standards ensure that work products are consistent, safe, and compatible across different practitioners and organizations.
Question 16: What is the primary purpose of quality specifications in technical work?
- To slow down production timelines
- To increase project costs unnecessarily
- To create employment for inspectors
- To define acceptable performance criteria and tolerances (Correct answer)
Correct answer: To define acceptable performance criteria and tolerances
Quality specifications establish clear criteria for acceptable work, including performance requirements and allowable tolerances.
Question 17: Which evaluation technique is MOST effective at uncovering undisclosed subprocessors or shadow IT within a vendor's environment?
- Reviewing the vendor's marketing website
- Limiting the evaluation to the vendor's primary data center
- Performing network traffic analysis and interviewing operational staff during an on-site visit (Correct answer)
- Asking the vendor's sales team to confirm subprocessor usage
Correct answer: Performing network traffic analysis and interviewing operational staff during an on-site visit
On-site observation combined with staff interviews surfaces operational realities that formal questionnaire responses may omit or obscure.
Question 18: Which of the following correctly describes the CTPRP exam format?
- Oral examination before a panel of experts
- Multiple-choice proctored exam (Correct answer)
- Open-book essay exam lasting 4 hours
- Portfolio submission with no written exam
Correct answer: Multiple-choice proctored exam
The CTPRP exam is a proctored multiple-choice examination designed to test knowledge of third-party risk management.
Question 19: Which scenario represents the MOST significant vendor governance failure?
- A vendor submits an annual compliance certification two weeks late
- A vendor accesses production systems beyond agreed scope without authorization (Correct answer)
- A vendor transitions account managers without advance notice
- A vendor requests a contract amendment to adjust service pricing
Correct answer: A vendor accesses production systems beyond agreed scope without authorization
Unauthorized access to production systems beyond the agreed scope represents a critical security and compliance failure that could trigger regulatory violations and data breach liability.
Question 20: What is the primary purpose of the CTPRP designation for a professional's career?
- Demonstrates proficiency in third-party risk management practices (Correct answer)
- Qualifies the holder to conduct financial audits
- Certifies expertise in cybersecurity penetration testing
- Validates knowledge of international trade compliance
Correct answer: Demonstrates proficiency in third-party risk management practices
The CTPRP designation validates a professional's competency in managing third-party vendor risks.
Question 21: Which technical skill is essential when reviewing a vendor's API security to prevent unauthorized data access?
- Assessing the vendor's disaster recovery plan narrative
- Analyzing vendor financial statements for liquidity
- Reviewing vendor employee training completion rates
- Evaluating OAuth 2.0 and token-based authentication implementations (Correct answer)
Correct answer: Evaluating OAuth 2.0 and token-based authentication implementations
OAuth 2.0 and proper token management are foundational API security controls that prevent unauthorized access to data shared between systems.
Question 22: What is the role of a code of ethics in the CTPRP profession?
- To create legal liability
- To restrict professional freedom
- To guide professional behavior and protect the public interest (Correct answer)
- To standardize pricing for services
Correct answer: To guide professional behavior and protect the public interest
A code of ethics establishes expectations for professional conduct and serves as a guide for ethical decision-making.
Question 23: Which of the following best describes the eligibility approach for the CTPRP exam?
- Restricted to members of the American Bar Association
- Open to professionals with relevant experience in TPRM, audit, compliance, or related fields (Correct answer)
- Requires a minimum of 10 years of risk management experience
- Requires sponsorship by a current CTPRP holder
Correct answer: Open to professionals with relevant experience in TPRM, audit, compliance, or related fields
The CTPRP is accessible to a broad range of professionals with relevant third-party risk, audit, or compliance backgrounds.
Question 24: In third-party risk management, what does a SOC 2 Type II report primarily assess?
- Vendor employee background check processes
- Operational effectiveness of controls over a defined period (Correct answer)
- Financial statement accuracy over a point in time
- Network penetration test results
Correct answer: Operational effectiveness of controls over a defined period
A SOC 2 Type II report evaluates whether a service organization's controls related to security, availability, and confidentiality operated effectively over a review period.
Question 25: In the TPRM lifecycle, what is the correct sequence of the initial phases?
- Identification β Due diligence β Contracting β Onboarding (Correct answer)
- Onboarding β Risk assessment β Contracting β Monitoring
- Assessment β Selection β Onboarding β Monitoring
- Planning β Identification β Assessment β Selection
Correct answer: Identification β Due diligence β Contracting β Onboarding
The standard TPRM lifecycle begins with identifying the need, conducting due diligence, formalizing the relationship through contracting, and then onboarding the vendor.
Question 26: In TPRM, which activity is central to the 'ongoing monitoring' phase of the vendor lifecycle?
- Conducting due diligence before vendor selection
- Continuously tracking vendor performance, risk changes, and control effectiveness (Correct answer)
- Negotiating initial contract terms with the vendor
- Offboarding the vendor and revoking access upon contract termination
Correct answer: Continuously tracking vendor performance, risk changes, and control effectiveness
Ongoing monitoring involves continuously reviewing key risk indicators, SLA performance, audit results, and external threat intelligence to detect emerging vendor risks.
Question 27: Which encryption standard is currently considered the minimum acceptable for protecting sensitive data in transit when transmitted by a third party?
- SSL 3.0
- TLS 1.0
- TLS 1.2 or higher (Correct answer)
- DES with 56-bit keys
Correct answer: TLS 1.2 or higher
TLS 1.2 and TLS 1.3 are the current industry-accepted minimum standards; older protocols like SSL 3.0 and TLS 1.0/1.1 have known vulnerabilities and are deprecated.
Question 28: Which type of third-party relationship typically poses the GREATEST concentration risk?
- A vendor providing non-critical administrative services to one department
- A vendor operating in a foreign jurisdiction with different regulations
- A single vendor supporting multiple critical business functions across the organization (Correct answer)
- A vendor shared with competitors in the same industry
Correct answer: A single vendor supporting multiple critical business functions across the organization
Concentration risk is highest when a single vendor supports multiple critical functions, meaning vendor failure could simultaneously disrupt numerous key operations.
Question 29: A CTPRP holder attends a Shared Assessments annual summit focused on vendor risk trends. Which CPE category does this activity fall under?
- Academic coursework in a non-related field
- Internal company training on HR policies
- Unrelated professional development
- Industry conference attendance relevant to TPRM (Correct answer)
Correct answer: Industry conference attendance relevant to TPRM
Attending industry conferences directly related to third-party risk management qualifies as CPE for CTPRP renewal.
Question 30: How does CTPRP certification benefit employers?
- It provides assurance of employee competence and commitment to professional standards (Correct answer)
- It eliminates the need for on-the-job training
- It guarantees perfect job performance
- It reduces salary requirements
Correct answer: It provides assurance of employee competence and commitment to professional standards
Certified employees have demonstrated verified knowledge and dedication to their profession, reducing risk for employers.
Question 31: How does passing the CTPRP exam benefit an organization employing the certified professional?
- It eliminates the need for third-party audits
- It provides assurance that staff can manage vendor risk effectively (Correct answer)
- It certifies the organization itself as a low-risk vendor
- It grants the organization automatic regulatory exemptions
Correct answer: It provides assurance that staff can manage vendor risk effectively
Having CTPRP-certified staff demonstrates the organization's commitment to mature third-party risk management practices.
Question 32: Which US federal law requires covered entities and their business associates to safeguard protected health information (PHI) shared with vendors?
- GLBA
- FCRA
- HIPAA (Correct answer)
- SOX
Correct answer: HIPAA
HIPAA requires covered entities to enter into Business Associate Agreements (BAAs) with vendors that access or process PHI, establishing mutual data protection obligations.
Question 33: In the context of TPRM, 'inherent risk' is BEST defined as:
- The financial cost of managing vendor relationships
- The risk exposure before any mitigating controls are considered (Correct answer)
- The residual risk remaining after all controls are applied
- Regulatory penalties already assessed against a vendor
Correct answer: The risk exposure before any mitigating controls are considered
Inherent risk represents the level of risk that exists in a vendor relationship based on factors like data access, criticality, and geography before any controls or mitigations are applied.
Question 34: Which scenario best demonstrates a CTPRP-aligned competency in practice?
- Designing a marketing campaign for a new product launch
- Negotiating employee salary benchmarks
- Conducting a risk-tiered assessment of a critical cloud vendor (Correct answer)
- Performing forensic accounting on internal financial records
Correct answer: Conducting a risk-tiered assessment of a critical cloud vendor
Risk-tiering and assessing critical vendors are core CTPRP competencies under the third-party risk lifecycle.
Question 35: Which tool category is most useful for continuous monitoring of a third party's external attack surface?
- Vendor invoice reconciliation tools
- GRC platform workflow automation
- Cyber ratings and external threat intelligence tools (Correct answer)
- Contract lifecycle management software
Correct answer: Cyber ratings and external threat intelligence tools
Cyber ratings platforms (e.g., BitSight, SecurityScorecard) continuously scan external-facing vendor assets to provide real-time risk signals.
Question 36: What type of questions are included in the CPTRP exam?
- Essay writing
- Short-answer questions
- Case study analysis
- Multiple-choice questions (Correct answer)
Correct answer: Multiple-choice questions
The CTPRP exam is structured to efficiently assess a candidate's knowledge across a broad spectrum of third-party risk management topics. Multiple-choice questions are a standard format for such professional certifications, allowing for objective scoring and comprehensive coverage of the curriculum within a defined time frame. This format tests understanding of concepts and best practices.
Question 37: When should an organization's own Business Impact Analysis (BIA) inform its third-party risk program?
- To set vendor pricing negotiations based on service criticality
- To identify which vendor services are critical and require stronger BCP/DR scrutiny (Correct answer)
- Only when a vendor has already experienced a disruption
- Only for vendors located in geographic regions prone to natural disasters
Correct answer: To identify which vendor services are critical and require stronger BCP/DR scrutiny
An internal BIA identifies which business processes are most critical and time-sensitive. Those findings directly inform third-party risk management by flagging which vendor services support critical processes β and therefore which vendor BCP/DR capabilities deserve the most rigorous scrutiny and the tightest RTO/RPO requirements.
Question 38: Which evaluation output is MOST useful for communicating third-party risk posture to senior management?
- A list of all open vendor tickets in the issue tracking system
- A risk-rated heat map with aggregated vendor scores and trend data (Correct answer)
- Raw questionnaire response data exported to a spreadsheet
- A detailed technical findings report from each vendor assessment
Correct answer: A risk-rated heat map with aggregated vendor scores and trend data
A heat map with aggregated scores and trends translates technical findings into executive-level insight for decision-making.
Question 39: When evaluating vendor contracts for concentration risk, which scenario represents the HIGHEST concern?
- Having multiple contracts with different legal jurisdictions
- Relying on a single cloud provider for 90% of core banking infrastructure with no viable alternative (Correct answer)
- Engaging three vendors for redundant janitorial services
- Using two different vendors for non-critical marketing services
Correct answer: Relying on a single cloud provider for 90% of core banking infrastructure with no viable alternative
Relying on one vendor for the vast majority of critical infrastructure creates dangerous concentration risk, as a vendor outage or failure would severely impact core business operations with no ready alternative.
Question 40: When assessing a cloud service provider's data segregation practices, which technical control confirms that one client's data cannot be accessed by another?
- Single sign-on (SSO) integration
- Shared credential vaulting
- Unified audit log retention
- Multi-tenant logical isolation with virtual private clouds (Correct answer)
Correct answer: Multi-tenant logical isolation with virtual private clouds
Logical isolation using virtual private clouds or similar segmentation ensures tenant data is separated and inaccessible across the shared infrastructure.
Question 41: Why is it important to validate that a vendor's business continuity plan (BCP) covers its key subcontractors and suppliers?
- Regulators require vendors to list all subcontractors in their BCP regardless of criticality
- BCPs are only required to cover the primary vendor's internal operations under most frameworks
- Subcontractors are always more resilient than primary vendors due to their smaller size
- A vendor's recovery may depend on subcontractor availability, making fourth-party disruptions a direct threat to service restoration (Correct answer)
Correct answer: A vendor's recovery may depend on subcontractor availability, making fourth-party disruptions a direct threat to service restoration
If critical subcontractors fail during a disruption, the vendor's own recovery timeline may be unachievable, cascading the impact to the organization.
Question 42: A TPRM analyst is evaluating a SaaS vendor's data retention and deletion practices. Which contractual provision is MOST important to include?
- Guaranteed 99.9% uptime SLA
- Vendor's commitment to annual price stability
- Priority support escalation path for production incidents
- Verifiable data deletion upon contract termination with certification of destruction (Correct answer)
Correct answer: Verifiable data deletion upon contract termination with certification of destruction
Certified data deletion upon contract termination ensures the organization's data is not retained or misused after the vendor relationship ends.
Question 43: When communicating third-party risk appetite boundaries to a vendor during contract negotiations, what is the most effective approach?
- Clearly state minimum security requirements, assessment expectations, and consequences for non-compliance in contract language (Correct answer)
- Disclose the organization's full internal risk register to the vendor
- Verbally communicate expectations without including them in the contract
- Allow the vendor to self-define acceptable risk thresholds
Correct answer: Clearly state minimum security requirements, assessment expectations, and consequences for non-compliance in contract language
Embedding security requirements, assessment expectations, and consequences for non-compliance into contract language creates enforceable, documented communication.
Question 44: A financial institution's vendor provides payment processing services. Which performance metric is most critical from a regulatory standpoint?
- Vendor office space square footage
- Vendor employee satisfaction scores
- Number of vendor marketing campaigns
- System availability and transaction processing uptime (Correct answer)
Correct answer: System availability and transaction processing uptime
Regulators focus on operational resilience metrics like uptime because payment system failures can cause systemic financial harm.
Question 45: Which governance body within an organization typically holds ultimate accountability for the TPRM program?
- The board of directors or senior executive leadership (Correct answer)
- The vendor management team
- The legal and compliance team
- The procurement department
Correct answer: The board of directors or senior executive leadership
Regulatory guidance consistently places ultimate accountability for TPRM program oversight with the board of directors and senior management, not operational teams.
Question 46: A vendor stores client data on servers located in a country with weak data privacy laws. What technical control best mitigates this risk?
- Periodic on-site audits
- Contractual data residency clauses only
- End-to-end encryption with client-managed keys (Correct answer)
- Requiring the vendor to purchase cyber insurance
Correct answer: End-to-end encryption with client-managed keys
End-to-end encryption with client-managed keys ensures data remains protected even if the host country's legal environment allows government access.
Question 47: What is a benefit of maintaining an active CPTRP certification?
- Eliminates the need for performance reviews.
- Provides access to mentorship programs.
- Simplifies vendor selection processes.
- Increases chances for promotions. (Correct answer)
Correct answer: Increases chances for promotions.
Maintaining an active CTPRP certification demonstrates a professional's ongoing commitment to expertise and continuous learning in a critical field. This dedication, coupled with validated skills in third-party risk management, makes them highly valuable to employers. Consequently, it often leads to increased recognition, more responsibilities, and greater opportunities for career advancement and promotions.
Question 48: Which of the following scenarios best illustrates 'operational risk' arising from a third-party relationship?
- A vendor's CEO faces criminal charges unrelated to the contracted services
- A vendor's stock price drops, reducing its market valuation
- A vendor raises its service fees above the contracted rate
- A vendor's data center outage causes the organization's customer-facing systems to go offline (Correct answer)
Correct answer: A vendor's data center outage causes the organization's customer-facing systems to go offline
Operational risk from third parties manifests when vendor failures in processes, systems, or people directly disrupt the organization's own operations.
Question 49: A company uses a tiered vendor classification system. Which tier typically requires the most frequent performance reviews?
- Tier 3 β low-risk, non-critical vendors
- Tier 1 β critical, high-risk vendors (Correct answer)
- All tiers require the same review frequency
- Tier 2 β moderate-risk vendors
Correct answer: Tier 1 β critical, high-risk vendors
Tier 1 critical vendors receive the most scrutiny because their failure could have material operational or regulatory impact.
Question 50: Which metric best measures a third party's ability to meet agreed service levels over time?
- Total contract value
- Service Level Agreement (SLA) compliance rate (Correct answer)
- Vendor's annual revenue growth
- Number of employees at the vendor
Correct answer: Service Level Agreement (SLA) compliance rate
SLA compliance rate directly quantifies whether the vendor is delivering on contractually agreed performance targets.
Question 51: Which element of a vendor contract directly defines the performance standards the vendor must meet?
- Master Service Agreement (MSA)
- Non-Disclosure Agreement (NDA)
- Statement of Work (SOW)
- Service-Level Agreement (SLA) (Correct answer)
Correct answer: Service-Level Agreement (SLA)
An SLA specifies measurable performance metrics such as uptime, response time, and resolution times that the vendor is contractually obligated to maintain.
Question 52: Which scenario represents a concentration risk finding in a third-party evaluation program?
- A vendor has offices in three different time zones
- The organization uses a different vendor for each business unit
- A vendor offers both SaaS and on-premise deployment options
- Sixty percent of critical business processes rely on a single cloud provider (Correct answer)
Correct answer: Sixty percent of critical business processes rely on a single cloud provider
Over-reliance on a single provider for the majority of critical processes creates systemic exposure if that provider experiences a disruption.
Question 53: What is the primary risk management objective of requiring vendors to carry cyber liability insurance?
- To transfer a portion of financial risk from a vendor-caused breach to the vendor's insurer (Correct answer)
- To guarantee the vendor will never have a data breach
- To satisfy ISO 27001 certification requirements
- To reduce the need for any contractual data protection clauses
Correct answer: To transfer a portion of financial risk from a vendor-caused breach to the vendor's insurer
Requiring cyber liability insurance ensures that if a vendor causes a data breach, there is an insurance mechanism to cover associated financial losses, partially transferring that risk away from your organization.
Question 54: What is the primary reason organizations assign weights to different KPIs in a vendor performance scorecard?
- To reflect the relative importance of each performance dimension to business objectives (Correct answer)
- To simplify reporting for the board
- To reduce the number of metrics tracked
- To avoid contractual disputes
Correct answer: To reflect the relative importance of each performance dimension to business objectives
Weighting KPIs ensures that more critical performance dimensions have a proportionally greater impact on the overall vendor score.
Question 55: How many continuing education (CE) hours are generally required per recertification cycle for the CTPRP credential?
- 50 hours
- 30 hours (Correct answer)
- 20 hours
- 10 hours
Correct answer: 30 hours
CTPRP holders are generally required to complete 30 continuing education hours per recertification period to maintain the credential.
Question 56: Which committee or group within an organization typically has oversight responsibility for the enterprise third-party risk management program?
- Individual business unit procurement staff only
- IT Help Desk team
- Marketing leadership team
- Risk Committee or Third-Party Risk Oversight Committee (Correct answer)
Correct answer: Risk Committee or Third-Party Risk Oversight Committee
A dedicated Risk Committee or Third-Party Risk Oversight Committee provides executive-level governance, ensuring TPRM is aligned with enterprise risk appetite and regulatory expectations.
Question 57: A vendor's Business Continuity Plan (BCP) should be reviewed by the contracting organization primarily to:
- Ensure the vendor can maintain services during disruptions in alignment with the organization's RTO/RPO (Correct answer)
- Confirm the vendor has adequate office space for staff
- Evaluate the vendor's employee benefits and retention programs
- Verify the vendor's financial solvency and credit rating
Correct answer: Ensure the vendor can maintain services during disruptions in alignment with the organization's RTO/RPO
Reviewing a vendor's BCP ensures their recovery time objectives (RTO) and recovery point objectives (RPO) are compatible with the contracting organization's own continuity requirements.
Question 58: What is the role of a code of ethics in the CTPRP profession?
- To restrict professional freedom
- To create legal liability
- To standardize pricing for services
- To guide professional behavior and protect the public interest (Correct answer)
Correct answer: To guide professional behavior and protect the public interest
A code of ethics establishes expectations for professional conduct and serves as a guide for ethical decision-making.
Question 59: Which practice BEST ensures ongoing vendor compliance throughout the contract lifecycle rather than only at onboarding?
- Conducting a single comprehensive audit at contract inception
- Relying on public regulatory filings to track vendor compliance status
- Requiring vendors to self-certify compliance on an annual basis only
- Implementing continuous monitoring with periodic reassessments tied to risk tier (Correct answer)
Correct answer: Implementing continuous monitoring with periodic reassessments tied to risk tier
Continuous monitoring combined with periodic reassessments based on risk tier ensures that changing risk profiles, new regulatory requirements, and emerging issues are identified throughout the relationship.
Question 60: A CTPRP holder's certification lapses due to non-renewal. What is the correct way to reference the credential?
- Use 'Former CTPRP' permanently on all professional materials
- Continue using CTPRP since the knowledge does not expire
- Use 'CTPRP (Inactive)' to show historical achievement
- Stop using the designation until it is reinstated (Correct answer)
Correct answer: Stop using the designation until it is reinstated
Lapsed credential holders must cease using the designation until they complete the reinstatement process.
Question 61: A CTPRP holder who fails to renew their credential by the expiration date will most likely:
- Enter a grace period and face a lapsed status if not renewed promptly (Correct answer)
- Automatically receive a one-year extension without penalty
- Be required to retake the full exam immediately
- Permanently lose the credential with no reinstatement option
Correct answer: Enter a grace period and face a lapsed status if not renewed promptly
Credentials that are not renewed by the expiration date typically enter a lapsed status, after which reinstatement may require additional steps or fees.
Question 62: In third-party risk management, what does 'inherent risk' represent?
- Risk before any controls or mitigations are considered (Correct answer)
- Risk identified during onboarding assessments
- Risk transferred to the vendor via contract
- Risk remaining after controls are applied
Correct answer: Risk before any controls or mitigations are considered
Inherent risk is the level of risk that exists in the absence of any controls, representing the raw exposure from engaging a third party.
Question 63: A CTPRP holder is asked to sign off on a third-party risk assessment completed by a junior analyst they supervised. What is their ethical obligation?
- Refuse to sign any work they did not personally complete
- Add a disclaimer noting they did not complete the work personally
- Sign without review if they trust the analyst
- Review the work to ensure quality and accuracy before attesting to it (Correct answer)
Correct answer: Review the work to ensure quality and accuracy before attesting to it
Supervising professionals bear responsibility for the quality of work they endorse and must review it adequately before signing.
Question 64: A financial institution discovers a vendor is subcontracting a critical function to a fourth party without notification. Which regulatory requirement does this MOST likely violate?
- Equal Credit Opportunity Act (ECOA) requirements
- Contract provisions requiring prior approval of subcontracting arrangements (Correct answer)
- Anti-money laundering (AML) provisions
- Community Reinvestment Act (CRA) obligations
Correct answer: Contract provisions requiring prior approval of subcontracting arrangements
Most regulatory frameworks require vendors to obtain prior approval before subcontracting critical functions, and contracts should contain provisions explicitly addressing fourth-party arrangements.
Question 65: SOC 2 reports, commonly reviewed during third-party due diligence, are based on which set of criteria?
- AICPA Trust Services Criteria (Correct answer)
- NIST SP 800-53 control catalog
- ISO 27001 control objectives
- PCI DSS requirements
Correct answer: AICPA Trust Services Criteria
SOC 2 reports are based on the AICPA Trust Services Criteria, which evaluate controls related to security, availability, processing integrity, confidentiality, and privacy.
Question 66: What is the purpose of a vendor risk register?
- To document identified risks, their likelihood, impact, and treatment for each vendor (Correct answer)
- To track vendor invoice payment status
- To list all vendors alphabetically for procurement records
- To record vendor employee headcount over time
Correct answer: To document identified risks, their likelihood, impact, and treatment for each vendor
A vendor risk register is a structured record that captures the risks associated with each vendor, their risk ratings, and the actions taken to treat or monitor those risks.
Question 67: A CTPRP professional is offered a gift by a vendor whose risk assessment they are conducting. What is the appropriate response?
- Accept the gift only after completing the assessment
- Accept the gift if its value is below $50
- Decline the gift to avoid any appearance of bias or compromise (Correct answer)
- Accept the gift and disclose it in the final report
Correct answer: Decline the gift to avoid any appearance of bias or compromise
Declining gifts from parties under assessment eliminates even the appearance of bias and upholds professional integrity.
Question 68: Which of the following provides the STRONGEST assurance that a vendor's disaster recovery plan will work when needed?
- The existence of a documented DR plan filed in the vendor's policy repository
- A written attestation from the vendor's CTO that the plan has been reviewed
- The vendor's purchase of DR software licenses
- Evidence that the vendor completed a full failover test within the last 12 months (Correct answer)
Correct answer: Evidence that the vendor completed a full failover test within the last 12 months
Documented plans and attestations confirm intent, but only tested plans provide evidence of actual operational effectiveness. A full failover test β where systems actually cut over to backup infrastructure β validates that the plan works in practice. Untested DR plans frequently fail during real events due to undetected gaps.
Question 69: Which of the following is an example of a KEY control in a vendor management policy related to data privacy compliance?
- Requiring vendors to use the organization's preferred font in reports
- Limiting vendor invoice submission to a specific portal
- Requiring vendors to submit quarterly sales forecasts
- Mandating that vendors execute a Data Processing Agreement (DPA) before handling personal data (Correct answer)
Correct answer: Mandating that vendors execute a Data Processing Agreement (DPA) before handling personal data
A DPA establishes legally binding privacy obligations consistent with regulations like GDPR and CCPA before personal data is shared with a vendor.
Question 70: In vendor governance, what does 'escalation path' refer to?
- The contract renewal negotiation process
- The vendor's internal promotion structure
- The vendor's plan to grow its business with your organization
- The defined process for raising unresolved vendor issues to higher authority (Correct answer)
Correct answer: The defined process for raising unresolved vendor issues to higher authority
An escalation path defines the steps and authorities involved when vendor performance issues, control failures, or contractual disputes cannot be resolved at the operational level.
Question 71: Which activity would NOT typically count toward CTPRP continuing education requirements?
- Attending a third-party risk management webinar
- Completing a general Microsoft Office skills course (Correct answer)
- Speaking at a risk management industry conference
- Publishing a peer-reviewed article on vendor risk
Correct answer: Completing a general Microsoft Office skills course
General software skills courses unrelated to third-party risk management do not qualify as relevant CE for the CTPRP credential.
Question 72: Under the CTPRP code of professional conduct, which situation most clearly represents a conflict of interest that must be disclosed?
- Holding multiple professional certifications simultaneously
- Working for a large corporation versus a small firm
- Owning stock in a vendor you are hired to assess for a client (Correct answer)
- Having more than 10 years of experience in the field
Correct answer: Owning stock in a vendor you are hired to assess for a client
Owning a financial interest in a vendor being assessed creates a direct conflict of interest requiring disclosure and possibly recusal.
Question 73: Which communication technique is most effective for verifying understanding?
- Repeating the same information louder
- Providing written instructions only
- Asking the person to explain the information back in their own words (Correct answer)
- Nodding and saying "I understand"
Correct answer: Asking the person to explain the information back in their own words
The teach-back method confirms understanding by having the person explain the information in their own words.
Question 74: In third-party risk management, what does a 'business continuity' contract requirement typically mandate?
- The vendor must obtain business interruption insurance only
- The vendor must relocate operations to the organization's facility during a disaster
- The vendor must maintain and test a business continuity plan (BCP) to ensure service availability during disruptions (Correct answer)
- The vendor must provide daily status reports regardless of disruptions
Correct answer: The vendor must maintain and test a business continuity plan (BCP) to ensure service availability during disruptions
Business continuity requirements oblige vendors to have tested BCPs that demonstrate their ability to maintain critical services during disruptions, protecting the organization from downstream impact.
Question 75: What is the significance of the Shared Assessments SIG (Standardized Information Gathering) questionnaire in CTPRP studies?
- It is a software testing protocol for cloud applications
- It is a government-mandated compliance checklist for federal contractors
- It is a key industry standard assessment tool for vendor risk evaluation (Correct answer)
- It is a tax filing tool for outsourced service providers
Correct answer: It is a key industry standard assessment tool for vendor risk evaluation
The SIG is a widely used industry questionnaire developed by Shared Assessments to standardize vendor risk assessments.
Question 76: What is the most important reason for keeping CTPRP CPE records organized throughout the renewal cycle rather than compiling them at the last minute?
- It reduces the risk of missing deadlines and ensures documentation is available in case of an audit (Correct answer)
- Organized records increase the likelihood of earning bonus CPE credits
- Certifying bodies require monthly CPE progress reports to be submitted
- Organized records are required to qualify for the CTPRP Distinguished Fellow designation
Correct answer: It reduces the risk of missing deadlines and ensures documentation is available in case of an audit
Maintaining organized records throughout the cycle prevents last-minute scrambles, ensures compliance, and provides immediate documentation if audited.
Question 77: A TPRM practitioner is building a vendor inventory. Which data element is MOST essential to capture for every third party?
- Number of vendor employees
- Vendor CEO's LinkedIn profile
- Vendor's marketing budget
- Type and criticality of services provided and data accessed (Correct answer)
Correct answer: Type and criticality of services provided and data accessed
Services provided and data accessed directly determine the vendor's risk classification, due diligence requirements, and monitoring frequency.
Question 78: What is the significance of 'business impact analysis' (BIA) in third-party risk management?
- It assesses the vendor's environmental and social responsibility practices
- It evaluates the vendor's financial health and creditworthiness
- It measures the regulatory compliance posture of a vendor
- It determines the consequences of disruption to services provided by a third party (Correct answer)
Correct answer: It determines the consequences of disruption to services provided by a third party
A BIA quantifies the operational, financial, and reputational impact of losing a third-party service, helping prioritize recovery efforts and vendor criticality ratings.
Question 79: What is the best approach when there is a language barrier with a client?
- Use a qualified professional interpreter (Correct answer)
- Skip detailed explanations and use gestures
- Speak louder and slower in English
- Use a family member for all translations
Correct answer: Use a qualified professional interpreter
Professional interpreters ensure accurate communication and maintain confidentiality, unlike informal translators.
Question 80: Which of the following topics is most closely aligned with the CTPRP curriculum?
- Equity derivatives trading strategies
- Real estate appraisal methodology
- Third-party onboarding and due diligence lifecycle (Correct answer)
- Machine learning algorithm development
Correct answer: Third-party onboarding and due diligence lifecycle
Third-party onboarding and due diligence are core components of the CTPRP body of knowledge.
Question 81: Which of the following activities would NOT typically qualify as an acceptable CPE source for CTPRP renewal?
- Completing a vendor risk assessment at work
- Attending a third-party risk management webinar
- Reading a TPRM-focused industry whitepaper
- Watching a personal finance documentary unrelated to risk (Correct answer)
Correct answer: Watching a personal finance documentary unrelated to risk
CPE activities must be relevant to third-party risk management or a related professional domain to count toward renewal.
Question 82: When regulators examine a financial institution's third-party risk management program, which deficiency is MOST likely to result in a Matters Requiring Attention (MRA)?
- Lack of a documented exit strategy for critical vendor relationships (Correct answer)
- Reviewing vendor contracts on a three-year rather than annual cycle
- Using standardized rather than customized vendor questionnaires
- Minor delays in vendor invoice processing
Correct answer: Lack of a documented exit strategy for critical vendor relationships
Regulators specifically look for documented exit strategies for critical vendors, as the absence of a transition plan represents a material gap that could leave the institution unable to maintain services if a vendor fails.
Question 83: How does publication of a TPRM-related article or whitepaper typically affect a CTPRP holder's CPE credits?
- Publications are never accepted as CPE activities
- Only peer-reviewed academic journal publications qualify
- Publishing professional content in a relevant field generally qualifies for CPE credits (Correct answer)
- Credits are awarded only if the publication is endorsed by Shared Assessments
Correct answer: Publishing professional content in a relevant field generally qualifies for CPE credits
Publishing professional content relevant to third-party risk management is generally accepted as a CPE-qualifying activity that reflects professional contribution.
Question 84: A CTPRP practitioner is building an evaluation schedule for 200 vendors. Which approach BEST balances thoroughness with resource efficiency?
- Apply tiered evaluation frequency and depth based on each vendor's risk rating (Correct answer)
- Evaluate only the top 10 vendors by contract value each year
- Outsource all evaluations to a single third-party audit firm
- Evaluate all 200 vendors annually with the same full assessment protocol
Correct answer: Apply tiered evaluation frequency and depth based on each vendor's risk rating
Risk-tiered scheduling directs the most rigorous, frequent evaluations toward high-risk vendors while using lighter-touch reviews for lower-risk relationships.
Question 85: Which of the following BEST describes the purpose of a right-to-audit clause in a third-party contract?
- It grants the organization the contractual right to inspect the vendor's facilities and records (Correct answer)
- It allows the vendor to audit the client's security controls
- It limits the scope of regulatory examinations to contracted services only
- It replaces the need for the vendor to obtain third-party certifications
Correct answer: It grants the organization the contractual right to inspect the vendor's facilities and records
A right-to-audit clause gives the organization contractual authority to verify vendor controls through direct inspection when needed.
Question 86: In TPRM theory, what does 'fourth-party risk' specifically refer to?
- Risk from the fourth tier of an organization's own internal supply chain
- Risk from vendors that serve four or more clients simultaneously
- Risk arising from subcontractors or service providers used by your direct vendors (Correct answer)
- Risk emerging in the fourth year of a vendor relationship
Correct answer: Risk arising from subcontractors or service providers used by your direct vendors
Fourth-party risk refers to the exposure created by subcontractors, sub-processors, and suppliers engaged by your direct (third-party) vendors.
Question 87: What is the key purpose of a right-to-audit clause in a vendor contract?
- To allow the client organization to audit the vendor's controls and compliance (Correct answer)
- To authorize government regulators to inspect vendor facilities on behalf of the client
- To permit third-party auditors to review the client's own employees
- To give the vendor the right to audit the client's financials
Correct answer: To allow the client organization to audit the vendor's controls and compliance
A right-to-audit clause contractually reserves the client's ability to conduct or commission audits of the vendor's controls, ensuring ongoing accountability beyond self-attestation.
Question 88: When a TPRM professional uses analogical reasoningβapplying lessons from one industry's vendor failures to their ownβwhich pitfall must they guard against?
- Assuming identical context when material differences exist between industries (Correct answer)
- Over-consulting with internal stakeholders
- Producing reports that are too detailed
- Gaining insights too quickly
Correct answer: Assuming identical context when material differences exist between industries
Analogical reasoning is powerful but fails when practitioners ignore material contextual differences between the source and target domains.
Question 89: What is 'residual risk' in the context of third-party risk management?
- Risk identified after a vendor breach has occurred
- Risk remaining after controls and mitigations have been applied (Correct answer)
- Risk passed to the vendor through indemnification clauses
- Risk excluded from the assessment scope
Correct answer: Risk remaining after controls and mitigations have been applied
Residual risk is the exposure that persists after all risk mitigation controls, contractual protections, and compensating measures have been implemented.
Question 90: What is the main purpose of an exit strategy or exit plan for a critical vendor?
- To plan the vendor's retirement from the industry
- To ensure business continuity if the vendor fails, exits the market, or the contract is terminated (Correct answer)
- To document the vendor's succession of account managers
- To prepare the vendor for an acquisition by your organization
Correct answer: To ensure business continuity if the vendor fails, exits the market, or the contract is terminated
An exit strategy for a critical vendor details how the organization will transition services to maintain continuity if the vendor relationship ends abruptly or is terminated for cause.
Question 91: What role does critical analysis play in understanding theory?
- Analysis should be avoided to prevent overthinking
- It enables deeper comprehension and the ability to evaluate and apply concepts (Correct answer)
- It is only needed for academic papers
- Critical analysis complicates simple ideas unnecessarily
Correct answer: It enables deeper comprehension and the ability to evaluate and apply concepts
Critical analysis develops deeper understanding, enabling practitioners to evaluate, adapt, and apply theoretical concepts effectively.
Question 92: Which section of the CPTRP exam covers compliance requirements?
- Vendor onboarding process
- Compliance requirements (Correct answer)
- Incident response planning
- Risk monitoring methods
Correct answer: Compliance requirements
The CTPRP exam covers various domains essential for third-party risk management. One dedicated section specifically addresses the complex landscape of regulatory and legal compliance that organizations must adhere to when engaging with third parties. This ensures professionals understand their obligations and how to manage third-party activities in line with relevant laws and industry standards.
Question 93: A contract manager notices that a vendor's insurance certificate on file has expired. What is the IMMEDIATE risk concern?
- Regulatory penalties will automatically be assessed against the organization
- The organization may have no recourse for losses caused by an uninsured vendor incident (Correct answer)
- The vendor may no longer meet minimum financial stability thresholds
- The vendor is likely also in breach of all SLA commitments
Correct answer: The organization may have no recourse for losses caused by an uninsured vendor incident
An expired insurance certificate leaves the organization exposed to unrecoverable losses if the vendor causes a covered incident during the lapse period.
Question 94: How should fundamental concepts be prioritized in learning?
- Learn everything simultaneously
- Master basics before advancing to complex topics (Correct answer)
- Fundamentals are only for beginners
- Skip basics and focus on advanced material
Correct answer: Master basics before advancing to complex topics
Strong fundamentals provide the foundation upon which all advanced knowledge and skills are built.
Question 95: Which body provides the CTPRP certification and sets the professional standards for third-party risk professionals in the US?
- CompTIA
- Shared Assessments (Correct answer)
- ISC2
- ISACA
Correct answer: Shared Assessments
Shared Assessments is the organization that administers the CTPRP certification and develops the tools and standards used by third-party risk professionals globally.
Question 96: Which of the following best describes the ethical obligation of a CTPRP holder regarding the currency of their knowledge?
- Credential holders are only obligated to know the material covered on the original exam
- Ethical obligations apply only to holders employed at financial institutions
- Ethics requirements are separate from and unrelated to CPE or renewal requirements
- Holders have a professional duty to stay current with evolving third-party risk standards and practices (Correct answer)
Correct answer: Holders have a professional duty to stay current with evolving third-party risk standards and practices
The CTPRP code of professional conduct requires holders to proactively maintain current knowledge, which is reinforced by the CPE renewal structure.
Question 97: Which phase of the third-party risk lifecycle involves assessing whether a prospective vendor's risk profile is acceptable before contracting?
- Contract remediation
- Offboarding
- Pre-contract due diligence (Correct answer)
- Ongoing monitoring
Correct answer: Pre-contract due diligence
Pre-contract due diligence evaluates inherent and residual risk before the organization commits to a vendor relationship.
Question 98: Which document formally defines the responsibilities, expectations, and performance metrics agreed upon between an organization and its third party?
- Statement of Work (SOW)
- Service Level Agreement (SLA) (Correct answer)
- Non-Disclosure Agreement (NDA)
- Master Service Agreement (MSA)
Correct answer: Service Level Agreement (SLA)
An SLA specifically captures measurable performance targets and accountability provisions between the organization and the third party.
Question 99: A CTPRP holder takes a TPRM-focused graduate-level university course. How many CPE credits would this most likely generate?
- None, as academic courses do not qualify for CPE credit
- Credits only if the course leads to a degree completion
- A flat rate of five credits regardless of course length
- Credits proportional to the course hours, such as one CPE per contact hour or credit hour (Correct answer)
Correct answer: Credits proportional to the course hours, such as one CPE per contact hour or credit hour
Formal academic coursework in a relevant field typically generates CPE credits on a proportional basis, such as one CPE credit per contact or credit hour.
Question 100: What is a significant outcome of hiring CPTRP-certified professionals?
- Streamlines project timelines.
- Increases organizational profit margins.
- Reduces third-party risks and enhances compliance. (Correct answer)
- Improves office management workflows.
Correct answer: Reduces third-party risks and enhances compliance.
CTPRP-certified professionals are specifically trained to identify, assess, and mitigate the diverse risks associated with third-party engagements. Their expertise ensures that organizations can proactively address potential vulnerabilities, comply with regulatory mandates, and protect their assets and reputation. This directly translates to a more secure and compliant operational environment.
CTPRP (Certified Third-Party Risk Professional) Exam
The CTPRP exam is administered by the Shared Assessments Program and is designed for professionals involved in third-party risk management and vendor governance. The exam covers third-party risk assessment, due diligence, regulatory compliance, vendor governance, and professional standards. Candidates must demonstrate knowledge of industry frameworks including SIG, CAIQ, and ISO 27001. The exam consists of approximately 100 questions with a passing score of 70%.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong β answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds