Third-Party Compliance Management Flashcards
7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Third-Party Compliance Management flashcards as text
An organization uses a cloud provider that experiences a data breach. Under GDPR, which party bears primary responsibility for notifying affected data subjects?
Answer: The organization as data controller
Under GDPR, the data controller (the organization) is responsible for notifying data subjects about breaches, even when caused by a data processor.
What is 'fourth-party risk' in the context of third-party compliance management?
Answer: Risk from vendors used by your direct third-party vendors
Fourth-party risk refers to risks arising from the subcontractors and service providers that your direct vendors rely on.
A compliance manager reviews a vendor's SOC 2 Type II report. What does this report primarily confirm?
Answer: The vendor's controls were designed and operated effectively over a period of time
SOC 2 Type II confirms that a service organization's controls were not only suitably designed but also operated effectively over a defined review period.
Which clause in a vendor contract helps ensure that compliance obligations pass through to the vendor's subcontractors?
Answer: Flow-down or pass-through clause
A flow-down or pass-through clause requires vendors to impose the same compliance obligations on their subcontractors that the organization imposed on them.
A vendor fails to report a security incident within the contractually required 24-hour window. What should the compliance team do FIRST?
Answer: Invoke the incident response plan and document the late notification
Invoking the incident response plan and documenting the breach of notification SLA is the appropriate first step before escalation decisions are made.
What is the key difference between a vendor assessment questionnaire and an on-site audit?
Answer: Questionnaires rely on vendor self-reporting; audits provide independent verification
Questionnaires depend on vendor self-disclosure, while on-site audits allow the organization to independently verify practices and controls.
Which metric is most useful for tracking the health of a third-party compliance program over time?
Answer: Percentage of vendors with overdue compliance assessments
The percentage of overdue compliance assessments directly reflects whether the program is keeping pace with its monitoring obligations.