Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Shared Assessments CTPRP Exam - Topic 1 Question 11 Discussion

An outsourcer's vendor risk assessment process includes all of the following EXCEPT:
D) Defining assessment frequency based on resource capacity
A) Establishing risk evaluation criteria based on company policy
B) Developing risk-tiered due diligence standards
C) Setting remediation timelines based on the severity level of findings

Shared Assessments CTPRP Exam - Topic 1 Question 11 Discussion

Actual exam question for Shared Assessments's CTPRP exam
Question #: 11
Topic #: 1
[All CTPRP Questions]

An outsourcer's vendor risk assessment process includes all of the following EXCEPT:

Show Suggested Answer Hide Answer
Suggested Answer: D

An outsourcer's vendor risk assessment process should include all the steps mentioned in options A, B, and C, as they are essential for ensuring a consistent, comprehensive, and effective evaluation of the vendor's performance, compliance, and risk profile. However, option D is not a necessary or recommended part of the vendor risk assessment process, as it does not reflect the actual level of risk posed by the vendor, but rather the availability of resources within the outsourcer's organization. Defining assessment frequency based on resource capacity could lead to under-assessing or over-assessing vendors, depending on the outsourcer's workload, budget, and staff. This could result in missing critical issues, wasting time and money, or creating gaps in the vendor oversight program. Therefore, option D is the correct answer, as it is the only one that does not belong to the vendor risk assessment process.Reference:The following resources support the verified answer and explanation:

Shared Assessments' CTPRP Job Guide, page 10, section 2.1.1, states that ''The frequency of assessments should be based on the risk tier of the third party, not on the availability of resources.''

Guide to Vendor Risk Assessment, section ''Step 3: Determine the Frequency of Vendor Risk Assessments'', explains that ''The frequency of vendor risk assessments should be based on the level of risk each vendor poses to your organization, not on the availability of resources or convenience.''

How to Conduct a Successful Vendor Risk Assessment in 9 Steps, section ''Step 8: Determine the Frequency of Vendor Risk Assessments'', advises that ''The frequency of vendor risk assessments should be based on the level of risk each vendor poses to your organization, not on the availability of resources or convenience.''


Contribute your Thoughts:

0/2000 characters
Stevie
1 day ago
D seems off, they should assess regularly regardless of resources.
upvoted 0 times
...
Ardella
7 days ago
I’m a bit confused, but I think establishing risk evaluation criteria is definitely part of the process, so it can't be the answer.
upvoted 0 times
...
Irma
12 days ago
This question reminds me of a practice question where we had to identify what doesn’t belong in a risk management framework. I think it’s about the timing of assessments.
upvoted 0 times
...
Brett
17 days ago
I’m not entirely sure, but I feel like defining assessment frequency based on resource capacity might not fit into the initial risk assessment process.
upvoted 0 times
...
Otis
22 days ago
I remember discussing risk assessment processes, and I think setting remediation timelines is usually part of the follow-up, not the assessment itself.
upvoted 0 times
...

Save Cancel