Minimum risk assessment standards for third party due diligence should be:
A.
Set by each business unit based on the number of vendors to be assessed
B.
Defined in the vendor/service provider contract or statement of work
C.
Established by the TPRM program based on the company’s risk tolerance and risk appetite
D.
Identified by procurement and required for all vendors and suppliers
The Answer Is:
C
This question includes an explanation.
Explanation:
According to the CTPRP Job Guide, the TPRM program should establish minimum risk assessment standards for third party due diligence based on the company’s risk tolerance and risk appetite. This means that the TPRM program should define the scope, depth, frequency, and methodology of the risk assessment process for different categories of third parties, taking into account the potential impact and likelihood of various risks. The risk assessment standards should be consistent, transparent, and aligned with the company’s strategic objectives and regulatory obligations. The TPRM program should also monitor and update the risk assessment standards as needed to reflect changes in the business environment, risk profile, and best practices. The other options are not correct because they do not reflect a holistic and risk-based approach to third party due diligence. Setting the standards by each business unit may result in inconsistency, duplication, or gaps in the risk assessment process. Defining the standards in the contract or statement of work may limit the flexibility and adaptability of the risk assessment process to changing circumstances. Identifying the standards by procurement may overlook the input and involvement of other stakeholders and functions in the risk assessment process. References:
CTPRP Job Guide, page 17
Third-Party Risk Management and ISO Requirements for 2022, section “Benefits of Implementing Risk Management”
Managing third-party risk through effective due diligence, section “Complying with regulators’ demands”
Third-Party Due Diligence Checklist: 3 Essential Steps, section “Step 2: Conduct a Risk Assessment”
CTPRP PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"