GRC Third-Party Risk Management 4 — Questions and Answers
Question 1: Which metric is MOST useful for measuring how quickly an organization identifies and responds to vendor-related security incidents?
- Vendor satisfaction score
- Mean Time to Detect and Respond (MTTR/MTTD) for vendor incidents (Correct answer)
- Number of vendors assessed per quarter
- Percentage of vendors with signed NDAs
Correct answer: Mean Time to Detect and Respond (MTTR/MTTD) for vendor incidents
MTTD and MTTR quantify detection and response speed, which are critical efficiency metrics for third-party incident management.
Question 2: Which of the following is an example of residual risk in a vendor relationship?
- The risk that exists before any controls are applied to the vendor
- The risk remaining after all agreed-upon controls and mitigations have been implemented (Correct answer)
- The risk transferred to the vendor through contract indemnification
- The risk identified during initial vendor due diligence but never accepted
Correct answer: The risk remaining after all agreed-upon controls and mitigations have been implemented
Residual risk is what remains after controls and mitigations are applied; it must be accepted, further mitigated, or transferred (e.g., via insurance).
Question 3: A technology vendor notifies your organization of a ransomware attack affecting their systems that store your customer data. What should be your organization's FIRST response step?
- Immediately terminate the vendor contract
- Activate the vendor incident response playbook and notify your legal and security teams (Correct answer)
- Post a public statement on social media
- Wait 72 hours for the vendor to resolve the issue independently
Correct answer: Activate the vendor incident response playbook and notify your legal and security teams
Activating the incident response playbook ensures a structured, timely response involving the right stakeholders, including legal and security teams.
Question 4: An inherent risk assessment of a vendor would evaluate risk:
- After all compensating controls are considered
- Before any mitigating controls or safeguards are applied (Correct answer)
- Based solely on the vendor's self-reported compliance posture
- Only for vendors classified as Tier 1 critical suppliers
Correct answer: Before any mitigating controls or safeguards are applied
Inherent risk represents the raw risk level associated with a vendor or activity before any controls are in place.
Question 5: Which of the following BEST supports a risk-based approach to vendor due diligence?
- Applying identical assessment questionnaires to all vendors regardless of criticality
- Scaling the depth and frequency of assessments based on the vendor's risk tier and data access (Correct answer)
- Outsourcing all due diligence to the vendor's own compliance team
- Limiting assessments to vendors that process financial data
Correct answer: Scaling the depth and frequency of assessments based on the vendor's risk tier and data access
A risk-based approach tailors due diligence intensity to each vendor's risk profile, ensuring efficient use of assessment resources.
Question 6: What is the purpose of a vendor scorecard in ongoing third-party risk management?
- To calculate the financial value each vendor provides
- To track and visualize key performance and risk indicators for a vendor over time (Correct answer)
- To rank vendors for preferred-supplier pricing negotiations
- To document vendor contact information in a centralized registry
Correct answer: To track and visualize key performance and risk indicators for a vendor over time
A vendor scorecard aggregates KPIs and KRIs into a dashboard that enables ongoing comparison of vendor performance and risk posture over time.
Question 7: Which contractual provision requires a vendor to notify the client within a specified timeframe if a data breach involving the client's data occurs?
- Limitation of liability clause
- Data breach notification clause (Correct answer)
- Force majeure clause
- Intellectual property ownership clause
Correct answer: Data breach notification clause
A data breach notification clause establishes the vendor's obligation to promptly inform the client of any security incident affecting the client's data, often aligning with regulatory timeframes.
Which metric is MOST useful for measuring how quickly an organization identifies and responds to vendor-related security incidents?