RCMS Third-Party Compliance Management 2 — Questions and Answers
Question 1: Which document formally establishes a third party's compliance obligations and sets enforceable standards within a vendor relationship?
- Service Level Agreement (SLA)
- Non-Disclosure Agreement (NDA)
- Vendor Code of Conduct (Correct answer)
- Memorandum of Understanding (MOU)
Correct answer: Vendor Code of Conduct
A Vendor Code of Conduct formally communicates and enforces compliance expectations including ethical, legal, and regulatory standards.
Question 2: A company discovers a key supplier is using sub-contractors not disclosed in the original contract. What is the primary compliance concern?
- Cost overruns from unauthorized procurement
- Lack of visibility into the extended supply chain (Correct answer)
- Breach of SLA response time commitments
- Improper invoice submission practices
Correct answer: Lack of visibility into the extended supply chain
Undisclosed sub-contractors create visibility gaps in the supply chain, exposing the organization to unknown compliance and risk exposure.
Question 3: Under the OCC's third-party risk management guidance, which lifecycle phase includes assessing a vendor's financial health and compliance history?
- Ongoing monitoring
- Contract negotiation
- Due diligence (Correct answer)
- Termination planning
Correct answer: Due diligence
Due diligence occurs before contracting and involves evaluating a vendor's financial stability, compliance record, and operational capacity.
Question 4: What is the primary purpose of including audit rights in a third-party vendor contract?
- To renegotiate pricing terms annually
- To allow the company to verify the vendor's compliance with agreed standards (Correct answer)
- To transfer liability for breaches to the vendor
- To establish the vendor's IT architecture requirements
Correct answer: To allow the company to verify the vendor's compliance with agreed standards
Audit rights give the organization contractual authority to inspect vendor operations and verify compliance with regulatory and contractual obligations.
Question 5: A compliance officer wants to tier vendors by risk level. Which factor is LEAST relevant to determining a vendor's risk tier?
- Access to sensitive customer data
- Geographic location of vendor operations
- Number of years the vendor has been in business (Correct answer)
- Volume of transactions processed by the vendor
Correct answer: Number of years the vendor has been in business
Years in business is not a direct indicator of risk level; data access, geography, and transaction volume are more material risk factors.
Question 6: Which regulatory framework specifically requires financial institutions to manage third-party service provider risks as an extension of their own compliance obligations?
- ISO 27001
- FFIEC IT Examination Handbook (Correct answer)
- PCI DSS Self-Assessment Questionnaire
- NIST Cybersecurity Framework
Correct answer: FFIEC IT Examination Handbook
The FFIEC IT Examination Handbook provides guidance requiring financial institutions to oversee third-party service providers as extensions of their own operations.
Question 7: When a vendor relationship is terminated, what compliance step is critical to protect sensitive data?
- Issuing a final payment without holdback
- Conducting a satisfaction survey with the vendor
- Ensuring data return or destruction per contractual terms (Correct answer)
- Notifying all internal departments of the new vendor selection
Correct answer: Ensuring data return or destruction per contractual terms
Data return or certified destruction upon termination prevents unauthorized retention of sensitive information and satisfies regulatory data protection requirements.
Which document formally establishes a third party's compliance obligations and sets enforceable standards within a vendor relationship?