RCMS Third-Party Compliance Management 3 — Questions and Answers
Question 1: An organization uses a cloud provider that experiences a data breach. Under GDPR, which party bears primary responsibility for notifying affected data subjects?
- The cloud provider as data processor
- The organization as data controller (Correct answer)
- The national supervisory authority
- The cloud provider's cybersecurity insurer
Correct answer: The organization as data controller
Under GDPR, the data controller (the organization) is responsible for notifying data subjects about breaches, even when caused by a data processor.
Question 2: What is 'fourth-party risk' in the context of third-party compliance management?
- Risk arising from the organization's own internal departments
- Risk from vendors used by your direct third-party vendors (Correct answer)
- Legal risk from four or more simultaneous vendor disputes
- Risk from the fourth contract year of a vendor relationship
Correct answer: Risk from vendors used by your direct third-party vendors
Fourth-party risk refers to risks arising from the subcontractors and service providers that your direct vendors rely on.
Question 3: A compliance manager reviews a vendor's SOC 2 Type II report. What does this report primarily confirm?
- The vendor's financial solvency and credit rating
- The vendor's controls were designed and operated effectively over a period of time (Correct answer)
- The vendor passed a one-time point-in-time security assessment
- The vendor meets ISO 14001 environmental standards
Correct answer: The vendor's controls were designed and operated effectively over a period of time
SOC 2 Type II confirms that a service organization's controls were not only suitably designed but also operated effectively over a defined review period.
Question 4: Which clause in a vendor contract helps ensure that compliance obligations pass through to the vendor's subcontractors?
- Force majeure clause
- Flow-down or pass-through clause (Correct answer)
- Indemnification clause
- Liquidated damages clause
Correct answer: Flow-down or pass-through clause
A flow-down or pass-through clause requires vendors to impose the same compliance obligations on their subcontractors that the organization imposed on them.
Question 5: A vendor fails to report a security incident within the contractually required 24-hour window. What should the compliance team do FIRST?
- Immediately terminate the vendor contract
- Invoke the incident response plan and document the late notification (Correct answer)
- Report the vendor to the relevant regulatory authority
- Suspend all data transfers to the vendor
Correct answer: Invoke the incident response plan and document the late notification
Invoking the incident response plan and documenting the breach of notification SLA is the appropriate first step before escalation decisions are made.
Question 6: What is the key difference between a vendor assessment questionnaire and an on-site audit?
- Questionnaires are only used for high-risk vendors; audits are for low-risk vendors
- Questionnaires rely on vendor self-reporting; audits provide independent verification (Correct answer)
- Audits assess financial risk while questionnaires focus on operational risk
- Questionnaires are regulatory requirements; audits are optional best practices
Correct answer: Questionnaires rely on vendor self-reporting; audits provide independent verification
Questionnaires depend on vendor self-disclosure, while on-site audits allow the organization to independently verify practices and controls.
Question 7: Which metric is most useful for tracking the health of a third-party compliance program over time?
- Total number of active vendor contracts
- Percentage of vendors with overdue compliance assessments (Correct answer)
- Average contract value per vendor tier
- Number of new vendors onboarded per quarter
Correct answer: Percentage of vendors with overdue compliance assessments
The percentage of overdue compliance assessments directly reflects whether the program is keeping pace with its monitoring obligations.
An organization uses a cloud provider that experiences a data breach.
Under GDPR, which party bears primary responsibility for notifying affected data subjects?