โ† All GRC Flashcard Decks

Third-Party Risk Management Flashcards

6 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Third-Party Risk Management flashcards as text
  1. A financial services firm is heavily dependent on a single cloud service provider for its core banking, data processing, and customer relationship management systems. This over-reliance on one vendor PRIMARILY exposes the firm to which specific type of risk?

    Answer: Concentration Risk

    Concentration risk arises when an organization becomes too dependent on a single third party for critical services. If that vendor fails, it could severely disrupt the organization's ability to operate. While this situation also involves operational, compliance, and reputational risks, concentration risk is the primary and most specific classification for over-reliance on a single vendor.

  2. Which of the following BEST defines fourth-party risk within a Third-Party Risk Management (TPRM) program?

    Answer: The risk posed by a vendor's subcontractor, whose failure could impact the services the primary vendor delivers to your organization.

    Fourth-party risk is the risk introduced by your vendors' vendors (i.e., their subcontractors or suppliers). An organization does not have a direct contractual relationship with these fourth parties, but their performance or security failures can still significantly impact the services received from the primary third-party vendor.

  3. During the TPRM lifecycle, which phase occurs *after* a vendor has been onboarded and is focused on continuously tracking their performance, security posture, and adherence to contractual obligations?

    Answer: Ongoing Monitoring

    Ongoing monitoring is the phase of the TPRM lifecycle that takes place after a vendor is onboarded. It involves continuously assessing the vendor to ensure they remain compliant and uphold the agreements established in the contract and to detect any new or emerging risks in real-time.

  4. A GRC professional is reviewing a contract for a new data analytics vendor. To ensure the organization can independently verify the vendor's security controls and compliance with data protection policies, which clause is MOST critical to include in the agreement?

    Answer: Right to Audit

    A 'Right to Audit' clause provides the organization with the contractual right to inspect and review the vendor's processes, controls, and records to verify compliance with the terms of the agreement. This is the most direct mechanism for validating a vendor's security and compliance posture. While the other clauses are important, they do not provide the explicit right to perform a verification audit.

  5. A healthcare organization is conducting due diligence on a potential vendor for processing patient medical records. Which of the following activities is a critical component of this due diligence process?

    Answer: Reviewing the vendor's SOC 2 report and compliance certifications.

    The due diligence process involves a thorough investigation of a potential vendor before signing a contract. A key part of this is evaluating their internal controls and compliance with relevant standards. Reviewing a SOC 2 report and other certifications (like ISO 27001 or HIPAA attestations) provides independent assurance of their security and data protection practices. The other options occur at different stages of the TPRM lifecycle.

  6. A manufacturing company is formalizing its TPRM program. The program manager insists that the process ends once a vendor contract is signed and the service is live. Why is this approach a significant GRC failure?

    Answer: It overlooks the need for ongoing monitoring, where new risks can emerge.

    A vendor's risk profile is not static; it can change at any time due to security incidents, financial instability, or changes in their own supply chain. A TPRM program that stops after onboarding is a failure because it completely ignores the critical phase of ongoing monitoring. Continuous oversight is required to identify and mitigate new or emerging risks throughout the entire relationship.