Third-Party Risk Management Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Third-Party Risk Management flashcards as text
Which document establishes the specific security and compliance requirements a vendor must meet as part of a contract?
Answer: Security Addendum / Exhibit
A security addendum or exhibit appended to a contract spells out the specific technical and compliance controls the vendor must satisfy.
A fourth-party risk is BEST described as:
Answer: Risk arising from your vendor's vendors and subcontractors
Fourth-party risk refers to the risks posed by subcontractors or suppliers that your direct (third-party) vendors rely upon.
During which TPRM lifecycle phase would an organization typically perform on-site audits and review vendor SOC 2 reports?
Answer: Ongoing monitoring
Ongoing monitoring includes periodic reviews of audit reports, on-site assessments, and continuous control validation throughout the vendor relationship.
What is the primary purpose of a vendor risk tiering model?
Answer: To allocate due diligence intensity based on the risk each vendor poses
Risk tiering ensures that high-risk vendors receive more rigorous due diligence while low-risk vendors receive lighter-touch reviews, optimizing resources.
Which of the following is a leading indicator that a vendor may be experiencing financial distress, increasing supply chain risk?
Answer: Vendor's credit rating is downgraded by a major agency
A credit rating downgrade signals deteriorating financial health, which can jeopardize a vendor's ability to fulfill contractual obligations.
An organization discovers that a critical SaaS vendor stores data in jurisdictions not listed in the contract. Which risk domain is MOST directly implicated?
Answer: Regulatory and compliance risk
Unauthorized data residency can violate data sovereignty laws (e.g., GDPR, CCPA), directly creating regulatory and compliance exposure.
The Right to Audit clause in a vendor contract primarily serves to:
Answer: Grant the organization the ability to examine the vendor's controls and records
A Right to Audit clause gives the contracting organization (or its designee) the authority to review the vendor's security controls, processes, and records.