RCMS Third-Party Compliance Management 4 — Questions and Answers
Question 1: Under the CFPB's vendor management expectations, financial institutions are held responsible for the actions of their service providers primarily because of which principle?
- Respondeat superior doctrine
- Nondelegable duty of consumer protection compliance (Correct answer)
- Strict liability for product defects
- Successor liability in mergers
Correct answer: Nondelegable duty of consumer protection compliance
The CFPB holds institutions responsible under a nondelegable duty concept, meaning compliance obligations cannot be outsourced away even when using third parties.
Question 2: A vendor operating in a high-risk jurisdiction is assessed for sanctions compliance. Which tool is most critical for this review?
- ISO 9001 quality management certification
- OFAC Specially Designated Nationals (SDN) list screening (Correct answer)
- SOC 1 Type I financial controls report
- PCI DSS merchant compliance certificate
Correct answer: OFAC Specially Designated Nationals (SDN) list screening
OFAC SDN list screening is essential to ensure the vendor or its principals are not subject to U.S. sanctions prohibitions.
Question 3: What is the main compliance risk of renewing a vendor contract without re-performing due diligence?
- Missing the opportunity to renegotiate pricing
- Failing to detect changes in the vendor's risk profile since initial onboarding (Correct answer)
- Losing preferred vendor status under procurement rules
- Creating duplicate contract records in the vendor management system
Correct answer: Failing to detect changes in the vendor's risk profile since initial onboarding
Vendor circumstances—financial health, ownership, regulatory violations—can change significantly, making re-diligence at renewal essential to updated risk assessment.
Question 4: Which element of a Business Associate Agreement (BAA) under HIPAA directly addresses third-party compliance obligations?
- The pricing and billing schedule for services rendered
- Required safeguards for protected health information (PHI) and breach reporting duties (Correct answer)
- The vendor's business continuity certification
- Intellectual property ownership of health records
Correct answer: Required safeguards for protected health information (PHI) and breach reporting duties
BAAs must specify the required administrative, physical, and technical safeguards for PHI and the vendor's obligation to report security incidents and breaches.
Question 5: An organization wants to assess concentration risk in its vendor portfolio. What does concentration risk refer to in this context?
- Over-reliance on a single vendor or vendor type for critical functions (Correct answer)
- The vendor's geographic concentration in one country
- High employee turnover concentrated in one vendor's account team
- Concentration of low-risk vendors requiring minimal oversight
Correct answer: Over-reliance on a single vendor or vendor type for critical functions
Concentration risk occurs when an organization relies too heavily on one vendor or a small group of vendors, creating a single point of failure for critical operations.
Question 6: A compliance specialist discovers that a vendor's employee who has access to the company's systems left the vendor's employment three months ago. What is the immediate compliance action?
- Request the vendor update their org chart
- Revoke the former employee's system access immediately and investigate potential unauthorized access (Correct answer)
- Send a vendor performance notice for the SLA breach
- Conduct a full vendor re-assessment before taking any action
Correct answer: Revoke the former employee's system access immediately and investigate potential unauthorized access
Immediate access revocation limits ongoing exposure, and an investigation determines whether any unauthorized access occurred during the access gap.
Question 7: Which practice best addresses the risk of vendor lock-in from a compliance continuity perspective?
- Requiring vendors to maintain a .com domain
- Maintaining portability of data and documented exit strategies in contracts (Correct answer)
- Limiting vendor contracts to no more than one year
- Using only domestic vendors to avoid international legal complications
Correct answer: Maintaining portability of data and documented exit strategies in contracts
Data portability requirements and documented exit strategies ensure the organization can transition away from a vendor without losing access to its own data or continuity of operations.
Under the CFPB's vendor management expectations, financial institutions are held responsible for the actions of their service providers primarily because of which principle?