A financial services company is implementing a vendor risk management program. Which THREE of the following are key components of an effective vendor risk assessment process? (Select THREE)
Contract compliance reviews verify that the vendor's actual security and privacy practises match the contractual obligations agreed at onboarding, providing the assurance the financial services company needs that third-party risk remains within its stated tolerance throughout the relationship.
Why this answer
Option A (Contract compliance reviews) is correct because an effective vendor risk assessment process must verify that the vendor continuously meets the security, privacy, and service-level obligations defined in the contract, ensuring accountability and detecting drift from agreed controls. Option B (Ongoing monitoring via annual reassessments) is correct because vendor risk is not static; periodic reassessments (at least annually, or upon significant changes) are needed to re-evaluate the vendor's security posture, financial health, and compliance status over the life of the relationship. Option D (Initial onboarding assessment including security questionnaires) is correct because due diligence before engagement is a foundational step—standardized questionnaires (e.g., SIG, CAIQ) help evaluate the vendor's controls, data handling practices, and risk level before any data or access is granted.
Option C is not among the marked correct answers because, while reviewing a vendor's cyber insurance policy can be a useful supplementary check, it is not one of the core components of the risk assessment process itself. Option E is not correct because a vendor self-assessment without independent validation is insufficient—it lacks verification and objectivity, which are essential to a credible risk assessment.
Exam trap
The trap here is that candidates often confuse risk transfer mechanisms (like cyber insurance) with risk assessment activities, leading them to select option C, when in fact insurance does not evaluate the vendor's actual security posture or operational risk.