GRC Third-Party Risk Management 5 — Questions and Answers
Question 1: Which of the following BEST describes vendor concentration risk in a supply chain context?
- Over-reliance on a single geographic region, vendor, or technology that creates systemic vulnerability (Correct answer)
- The risk that a vendor's pricing will increase significantly at contract renewal
- Exposure to foreign exchange fluctuations when paying international vendors
- Risk that multiple vendors will bid on the same contract simultaneously
Correct answer: Over-reliance on a single geographic region, vendor, or technology that creates systemic vulnerability
Vendor concentration risk arises when an organization depends too heavily on one source, geography, or platform, making it vulnerable to widespread disruption if that source fails.
Question 2: A financial institution uses a TPRM program to comply with OCC Bulletin 2013-29. This guidance primarily addresses:
- Anti-money laundering controls for payment processors
- Risk management expectations for third-party relationships in banking (Correct answer)
- Export control compliance for technology vendors
- Environmental, Social, and Governance (ESG) disclosures for suppliers
Correct answer: Risk management expectations for third-party relationships in banking
OCC Bulletin 2013-29 establishes comprehensive third-party risk management expectations for national banks, covering due diligence, contract provisions, and oversight.
Question 3: When assessing a cloud service provider, which security framework attestation is MOST relevant for evaluating data protection and availability controls?
- ISO 14001 (Environmental Management)
- SOC 2 Trust Services Criteria (Security, Availability, Confidentiality) (Correct answer)
- ISO 9001 (Quality Management)
- SA8000 (Social Accountability)
Correct answer: SOC 2 Trust Services Criteria (Security, Availability, Confidentiality)
SOC 2 evaluates cloud provider controls against Trust Services Criteria including Security, Availability, and Confidentiality — the most relevant domains for data protection.
Question 4: Which activity should occur BEFORE a new high-risk vendor is granted access to production systems?
- Annual renewal of the vendor's business license
- Completion of due diligence, contract execution, and security control validation (Correct answer)
- Issuance of a purchase order for vendor services
- Scheduling of the vendor's quarterly business review
Correct answer: Completion of due diligence, contract execution, and security control validation
High-risk vendors must pass due diligence, have a signed contract with required provisions, and demonstrate effective security controls before accessing production environments.
Question 5: An organization's TPRM policy requires vendors with access to PII to complete an annual security questionnaire. A vendor refuses to complete it. What is the BEST course of action?
- Accept the vendor's refusal and document the exception
- Escalate the issue; consider requiring an independent audit or terminating the relationship if the vendor remains non-compliant (Correct answer)
- Remove the PII access requirement from the vendor's contract
- Allow the vendor a permanent exemption if they are a large enterprise
Correct answer: Escalate the issue; consider requiring an independent audit or terminating the relationship if the vendor remains non-compliant
Non-compliance with assessment requirements is a material risk issue that should be escalated; the organization may need to enforce contractual remedies or exit the relationship.
Question 6: What does 'vendor lock-in' risk refer to in the context of third-party risk management?
- A vendor physically locking access to leased equipment upon contract expiration
- Difficulty or high cost of transitioning away from a vendor due to deep technical or contractual dependencies (Correct answer)
- A vendor refusing to allow subcontracting arrangements
- Regulatory prohibitions on switching cloud providers in regulated industries
Correct answer: Difficulty or high cost of transitioning away from a vendor due to deep technical or contractual dependencies
Vendor lock-in occurs when proprietary technologies, data formats, or exit barriers make switching vendors prohibitively expensive or complex, reducing organizational flexibility.
Question 7: Which of the following is the MOST effective way to reduce supply chain risk introduced by open-source software components used by a vendor?
- Prohibit all vendor use of open-source software via contract
- Require vendors to maintain a Software Bill of Materials (SBOM) and a process for patching vulnerable components (Correct answer)
- Accept open-source risk as unmanageable and focus only on proprietary vendor software
- Require vendors to purchase commercial licenses for all open-source components
Correct answer: Require vendors to maintain a Software Bill of Materials (SBOM) and a process for patching vulnerable components
An SBOM provides transparency into which open-source components are in use, enabling rapid identification and remediation when vulnerabilities (like Log4Shell) are disclosed.
Which of the following BEST describes vendor concentration risk in a supply chain context?