
Ultimate access to all questions.
Q-29. The senior management team of a small regional bank has established a committee to review procedures and implement best practices related to entering into significant contracts with third-party vendors. The committee is reviewing one proposed relationship with a third-party vendor who would have a significant responsibility for marketing the bank's financial products to potential customers. In establishing policies to reduce the operational risk associated with this potential vendor contract, which of the following recommendations would be most appropriate?
A
The bank should review all third-party audit reports of a vendor that are publicly available.
B
The bank should ensure that a vendor's sales representatives are compensated mainly with commissions from the sale of the bank's products.
C
The bank should prevent a third-party vendor from having access to any of its critical systems or data.