Third-Party Compliance Management Flashcards
7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Third-Party Compliance Management flashcards as text
Which document formally establishes a third party's compliance obligations and sets enforceable standards within a vendor relationship?
Answer: Vendor Code of Conduct
A Vendor Code of Conduct formally communicates and enforces compliance expectations including ethical, legal, and regulatory standards.
A company discovers a key supplier is using sub-contractors not disclosed in the original contract. What is the primary compliance concern?
Answer: Lack of visibility into the extended supply chain
Undisclosed sub-contractors create visibility gaps in the supply chain, exposing the organization to unknown compliance and risk exposure.
Under the OCC's third-party risk management guidance, which lifecycle phase includes assessing a vendor's financial health and compliance history?
Answer: Due diligence
Due diligence occurs before contracting and involves evaluating a vendor's financial stability, compliance record, and operational capacity.
What is the primary purpose of including audit rights in a third-party vendor contract?
Answer: To allow the company to verify the vendor's compliance with agreed standards
Audit rights give the organization contractual authority to inspect vendor operations and verify compliance with regulatory and contractual obligations.
A compliance officer wants to tier vendors by risk level. Which factor is LEAST relevant to determining a vendor's risk tier?
Answer: Number of years the vendor has been in business
Years in business is not a direct indicator of risk level; data access, geography, and transaction volume are more material risk factors.
Which regulatory framework specifically requires financial institutions to manage third-party service provider risks as an extension of their own compliance obligations?
Answer: FFIEC IT Examination Handbook
The FFIEC IT Examination Handbook provides guidance requiring financial institutions to oversee third-party service providers as extensions of their own operations.
When a vendor relationship is terminated, what compliance step is critical to protect sensitive data?
Answer: Ensuring data return or destruction per contractual terms
Data return or certified destruction upon termination prevents unauthorized retention of sensitive information and satisfies regulatory data protection requirements.