← All GRC Flashcard Decks

Third-Party Risk Management Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Third-Party Risk Management flashcards as text
  1. Which of the following BEST describes vendor concentration risk in a supply chain context?

    Answer: Over-reliance on a single geographic region, vendor, or technology that creates systemic vulnerability

    Vendor concentration risk arises when an organization depends too heavily on one source, geography, or platform, making it vulnerable to widespread disruption if that source fails.

  2. A financial institution uses a TPRM program to comply with OCC Bulletin 2013-29. This guidance primarily addresses:

    Answer: Risk management expectations for third-party relationships in banking

    OCC Bulletin 2013-29 establishes comprehensive third-party risk management expectations for national banks, covering due diligence, contract provisions, and oversight.

  3. When assessing a cloud service provider, which security framework attestation is MOST relevant for evaluating data protection and availability controls?

    Answer: SOC 2 Trust Services Criteria (Security, Availability, Confidentiality)

    SOC 2 evaluates cloud provider controls against Trust Services Criteria including Security, Availability, and Confidentiality — the most relevant domains for data protection.

  4. Which activity should occur BEFORE a new high-risk vendor is granted access to production systems?

    Answer: Completion of due diligence, contract execution, and security control validation

    High-risk vendors must pass due diligence, have a signed contract with required provisions, and demonstrate effective security controls before accessing production environments.

  5. An organization's TPRM policy requires vendors with access to PII to complete an annual security questionnaire. A vendor refuses to complete it. What is the BEST course of action?

    Answer: Escalate the issue; consider requiring an independent audit or terminating the relationship if the vendor remains non-compliant

    Non-compliance with assessment requirements is a material risk issue that should be escalated; the organization may need to enforce contractual remedies or exit the relationship.

  6. What does 'vendor lock-in' risk refer to in the context of third-party risk management?

    Answer: Difficulty or high cost of transitioning away from a vendor due to deep technical or contractual dependencies

    Vendor lock-in occurs when proprietary technologies, data formats, or exit barriers make switching vendors prohibitively expensive or complex, reducing organizational flexibility.

  7. Which of the following is the MOST effective way to reduce supply chain risk introduced by open-source software components used by a vendor?

    Answer: Require vendors to maintain a Software Bill of Materials (SBOM) and a process for patching vulnerable components

    An SBOM provides transparency into which open-source components are in use, enabling rapid identification and remediation when vulnerabilities (like Log4Shell) are disclosed.