← All RCMS Flashcard Decks

Third-Party Compliance Management Flashcards

7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Third-Party Compliance Management flashcards as text
  1. Under the CFPB's vendor management expectations, financial institutions are held responsible for the actions of their service providers primarily because of which principle?

    Answer: Nondelegable duty of consumer protection compliance

    The CFPB holds institutions responsible under a nondelegable duty concept, meaning compliance obligations cannot be outsourced away even when using third parties.

  2. A vendor operating in a high-risk jurisdiction is assessed for sanctions compliance. Which tool is most critical for this review?

    Answer: OFAC Specially Designated Nationals (SDN) list screening

    OFAC SDN list screening is essential to ensure the vendor or its principals are not subject to U.S. sanctions prohibitions.

  3. What is the main compliance risk of renewing a vendor contract without re-performing due diligence?

    Answer: Failing to detect changes in the vendor's risk profile since initial onboarding

    Vendor circumstances—financial health, ownership, regulatory violations—can change significantly, making re-diligence at renewal essential to updated risk assessment.

  4. Which element of a Business Associate Agreement (BAA) under HIPAA directly addresses third-party compliance obligations?

    Answer: Required safeguards for protected health information (PHI) and breach reporting duties

    BAAs must specify the required administrative, physical, and technical safeguards for PHI and the vendor's obligation to report security incidents and breaches.

  5. An organization wants to assess concentration risk in its vendor portfolio. What does concentration risk refer to in this context?

    Answer: Over-reliance on a single vendor or vendor type for critical functions

    Concentration risk occurs when an organization relies too heavily on one vendor or a small group of vendors, creating a single point of failure for critical operations.

  6. A compliance specialist discovers that a vendor's employee who has access to the company's systems left the vendor's employment three months ago. What is the immediate compliance action?

    Answer: Revoke the former employee's system access immediately and investigate potential unauthorized access

    Immediate access revocation limits ongoing exposure, and an investigation determines whether any unauthorized access occurred during the access gap.

  7. Which practice best addresses the risk of vendor lock-in from a compliance continuity perspective?

    Answer: Maintaining portability of data and documented exit strategies in contracts

    Data portability requirements and documented exit strategies ensure the organization can transition away from a vendor without losing access to its own data or continuity of operations.

Third-Party Compliance Management Flashcards — RCMS Study Cards with Answers