Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Shared Assessments CTPRP Exam - Topic 1 Question 11 Discussion

An outsourcer's vendor risk assessment process includes all of the following EXCEPT:
D) Defining assessment frequency based on resource capacity
A) Establishing risk evaluation criteria based on company policy
B) Developing risk-tiered due diligence standards
C) Setting remediation timelines based on the severity level of findings

Shared Assessments CTPRP Exam - Topic 1 Question 11 Discussion

Actual exam question for Shared Assessments's CTPRP exam
Question #: 11
Topic #: 1
[All CTPRP Questions]

An outsourcer's vendor risk assessment process includes all of the following EXCEPT:

Show Suggested Answer Hide Answer
Suggested Answer: D

An outsourcer's vendor risk assessment process should include all the steps mentioned in options A, B, and C, as they are essential for ensuring a consistent, comprehensive, and effective evaluation of the vendor's performance, compliance, and risk profile. However, option D is not a necessary or recommended part of the vendor risk assessment process, as it does not reflect the actual level of risk posed by the vendor, but rather the availability of resources within the outsourcer's organization. Defining assessment frequency based on resource capacity could lead to under-assessing or over-assessing vendors, depending on the outsourcer's workload, budget, and staff. This could result in missing critical issues, wasting time and money, or creating gaps in the vendor oversight program. Therefore, option D is the correct answer, as it is the only one that does not belong to the vendor risk assessment process.Reference:The following resources support the verified answer and explanation:

Shared Assessments' CTPRP Job Guide, page 10, section 2.1.1, states that ''The frequency of assessments should be based on the risk tier of the third party, not on the availability of resources.''

Guide to Vendor Risk Assessment, section ''Step 3: Determine the Frequency of Vendor Risk Assessments'', explains that ''The frequency of vendor risk assessments should be based on the level of risk each vendor poses to your organization, not on the availability of resources or convenience.''

How to Conduct a Successful Vendor Risk Assessment in 9 Steps, section ''Step 8: Determine the Frequency of Vendor Risk Assessments'', advises that ''The frequency of vendor risk assessments should be based on the level of risk each vendor poses to your organization, not on the availability of resources or convenience.''


Contribute your Thoughts:

0/2000 characters
Vonda
4 hours ago
D doesn’t fit with the others.
upvoted 0 times
...
Lucy
5 days ago
Same here, D seems off.
upvoted 0 times
...
Susana
10 days ago
I’m leaning towards D.
upvoted 0 times
...
Devora
16 days ago
I agree, it’s confusing.
upvoted 0 times
...
Rebbecca
21 days ago
I think the question is tricky.
upvoted 0 times
...
Kerrie
26 days ago
C is crucial, timelines matter for remediation!
upvoted 0 times
...
Shawnta
1 month ago
I think D is actually the right answer here.
upvoted 0 times
...
Evan
1 month ago
Wait, are you telling me they don't define assessment frequency? That's surprising!
upvoted 0 times
...
Harrison
1 month ago
Totally agree, A, B, and C are essential steps!
upvoted 0 times
...
Stevie
2 months ago
D seems off, they should assess regularly regardless of resources.
upvoted 0 times
...
Ardella
2 months ago
I’m a bit confused, but I think establishing risk evaluation criteria is definitely part of the process, so it can't be the answer.
upvoted 0 times
...
Irma
2 months ago
This question reminds me of a practice question where we had to identify what doesn’t belong in a risk management framework. I think it’s about the timing of assessments.
upvoted 0 times
...
Brett
2 months ago
I’m not entirely sure, but I feel like defining assessment frequency based on resource capacity might not fit into the initial risk assessment process.
upvoted 0 times
...
Otis
2 months ago
I remember discussing risk assessment processes, and I think setting remediation timelines is usually part of the follow-up, not the assessment itself.
upvoted 0 times
...

Save Cancel