โ† All GRC Flashcard Decks

Third-Party Risk Management Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Third-Party Risk Management flashcards as text
  1. Which document establishes the specific security and compliance requirements a vendor must meet as part of a contract?

    Answer: Security Addendum / Exhibit

    A security addendum or exhibit appended to a contract spells out the specific technical and compliance controls the vendor must satisfy.

  2. A fourth-party risk is BEST described as:

    Answer: Risk arising from your vendor's vendors and subcontractors

    Fourth-party risk refers to the risks posed by subcontractors or suppliers that your direct (third-party) vendors rely upon.

  3. During which TPRM lifecycle phase would an organization typically perform on-site audits and review vendor SOC 2 reports?

    Answer: Ongoing monitoring

    Ongoing monitoring includes periodic reviews of audit reports, on-site assessments, and continuous control validation throughout the vendor relationship.

  4. What is the primary purpose of a vendor risk tiering model?

    Answer: To allocate due diligence intensity based on the risk each vendor poses

    Risk tiering ensures that high-risk vendors receive more rigorous due diligence while low-risk vendors receive lighter-touch reviews, optimizing resources.

  5. Which of the following is a leading indicator that a vendor may be experiencing financial distress, increasing supply chain risk?

    Answer: Vendor's credit rating is downgraded by a major agency

    A credit rating downgrade signals deteriorating financial health, which can jeopardize a vendor's ability to fulfill contractual obligations.

  6. An organization discovers that a critical SaaS vendor stores data in jurisdictions not listed in the contract. Which risk domain is MOST directly implicated?

    Answer: Regulatory and compliance risk

    Unauthorized data residency can violate data sovereignty laws (e.g., GDPR, CCPA), directly creating regulatory and compliance exposure.

  7. The Right to Audit clause in a vendor contract primarily serves to:

    Answer: Grant the organization the ability to examine the vendor's controls and records

    A Right to Audit clause gives the contracting organization (or its designee) the authority to review the vendor's security controls, processes, and records.