CCAR-P Governance, Safety, and Risk Management Practice Question
Which governance practice is most effective for managing 'Third-Party Model Risk'?
⚠ Common exam trap
Candidates often suggest that the organization can 'fix' the third-party model. They fail to recognize that the organization's control is limited to contractual agreements and vendor oversight.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conducting vendor due diligence and establishing SLAs.
Managing third-party model risk involves creating a clear vendor management strategy that includes rigorous due diligence, transparency requirements, and contractual guarantees regarding safety and performance. By treating AI providers as critical vendors, organizations ensure that the model provider is held accountable for their platform's safety. This allows the organization to align the provider's capabilities with their own internal risk tolerance and compliance requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allowing free access to all models.
Why it's wrong here
Unrestricted access to any available model is a major governance failure. Without an evaluation process or vendor vetting, the organization cannot ensure that the model meets its safety, security, or legal requirements. This creates massive enterprise risk and should be prevented by strict procurement policies.
- ✓
Conducting vendor due diligence and establishing SLAs.
Why this is correct
Vendor due diligence is the standard governance approach for managing third-party risk. It involves assessing the provider's safety practices, data handling, and reliability. Service Level Agreements (SLAs) then set clear expectations for performance, security, and support, ensuring the provider meets the needs of the enterprise's risk management framework.
- ✗
Only using internal models.
Why it's wrong here
While internal models offer more control, they are often impractical due to the massive cost and expertise required for training. Most organizations utilize third-party APIs. The key is not to avoid them entirely, but to have a robust governance process for vetting and managing these third-party integrations effectively.
- ✗
Relying on public trust instead of contracts.
Why it's wrong here
Public reputation is not a substitute for legal and contractual security. When integrating third-party models into enterprise workflows, formal agreements are necessary to define responsibilities for security, data privacy, and compliance, protecting the organization in the event of a failure or incident involving the third-party provider.
About these practice questions
This CCAR-P question is part of Courseiva's 262-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.