1. Third-Party Risk advanced

    A consumer finance platform depends on many third parties whose failures are its regulatory problem. What must the architecture provide?

    2 min answer slicethird-partyisolationevidence
  2. Third-Party Risk beginner

    A supplier provides an ISO 27001 certificate in response to your security assessment. What does the certificate actually tell you, and what does it not?

    3 min answer certificationthird-party-riskassurancescope
  3. Third-Party Risk advanced

    A supplier's compromise gives an attacker access to your systems. What should the architecture have done?

    1 min answer third-party-risksupply-chainleast-privilegemonitoring
  4. Third-Party Risk advanced

    A support team enables an AI summarisation feature in its helpdesk tool. Three weeks later a customer asks for your list of subprocessors and a security review finds that ticket contents, including customer personal data, have been sent to a model provider in another jurisdiction with a 30-day retention default. What failed?

    3 min answer subprocessorsaidata-transferegress-control
  5. Third-Party Risk advanced

    In April 2022 a maintenance script at Atlassian permanently deleted 883 sites belonging to 775 customers inside 23 minutes, and the last customer was not restored until 18 April. Backups were fine and almost no data was lost. What made recovery the hard part, and what should that change in how you evaluate a vendor?

    2 min answer atlassianmulti-tenantrestorerto
  6. Third-Party Risk intermediate

    Your KYC verification vendor is down for six hours. Customer onboarding stops. The board asks why a vendor outage became your outage.

    2 min answer vendorsresiliencedegradation