Home » Articles posted by Shraddha Khedkar

Author Archives: Shraddha Khedkar

News/Events@HB

6th Masterclass by International TPRM Alliance

0%
11

6th TPRM Masterclass

6th TPRM Masterclass

Please enter your full name, email address and location for certificate/score-generations! You will receive a certificate only if you score above 70%.

1 / 28

Category: 6th TPRM Masterclass

1. The “Data use, training and processing location” clause restricts the supplier from doing what, absent the Customer's prior written authorization?

2 / 28

Category: 6th TPRM Masterclass

2. Which pairing correctly matches a “Contractual guardrails for AI use” theme with its own description?

3 / 28

Category: 6th TPRM Masterclass

3. Under “Continuity, termination and exit,” what must the supplier's business continuity and disaster recovery arrangements be consistent with?

4 / 28

Category: 6th TPRM Masterclass

4. The “Eight diligence gates” group gates 5–6 under which theme?

5 / 28

Category: 6th TPRM Masterclass

5. What was the outcome of EEOC v. iTutor Group, Inc., et al.?

6 / 28

Category: 6th TPRM Masterclass

6. Contract terms across the chain” lists four themes. Which theme covers “Notice, assessment rights, remediation and proportionate suspension

7 / 28

Category: 6th TPRM Masterclass

7. In the agentic banking assistant case walkthrough, what triggered the unauthorized tool call?

8 / 28

Category: 6th TPRM Masterclass

8. Under the “Dependency disclosure and subcontracting” clause, what must the supplier maintain?

9 / 28

Category: 6th TPRM Masterclass

9. What best defines a “Third party” in the tiering of AI supply-chain relationships?

10 / 28

Category: 6th TPRM Masterclass

10. Per the “Material changes and model substitution” clause, what illustrative minimum notice period is suggested for a material change?

11 / 28

Category: 6th TPRM Masterclass

11. In “Structuring the AI contract,” which party is described as remaining answerable for the contracted delivery chain?

12 / 28

Category: 6th TPRM Masterclass

12. Under “Audit, evidence and regulatory cooperation,” what must the supplier secure from material subcontractors?

13 / 28

Category: 6th TPRM Masterclass

13. Under “Evaluation and human oversight,” what must the supplier provide before deployment and after any material change affecting acceptance criteria?

14 / 28

Category: 6th TPRM Masterclass

14. According to the AI roles terminology, what is an “AI model”?

15 / 28

Category: 6th TPRM Masterclass

15. Which of the following is NOT one of the four elements of the “operating model for AI dependencies”?

16 / 28

Category: 6th TPRM Masterclass

16. Which pairing correctly matches a risk path with its example, per “Six ways risk reaches the business”?

17 / 28

Category: 4TPRMMasterclass

Which topics would you like to see covered in future roundtables or masterclasses?
e.g.,

  • 17. Third-Party Cyber Risk & Continuous Monitoring
  • AI Risk in Vendor Ecosystems
  • Cloud & SaaS Risk Management
  • Regulatory Compliance (e.g., outsourcing, data protection)
  • Fourth-Party / Concentration Risk
  • Incident & Breach Management involving vendors
  • Other (please specify): __________

18 / 28

Category: 4TPRMMasterclass

18. Please share your feedback on the event

  • What did you find most valuable?
  • What could be improved?
  • Any suggestions for future sessions?

19 / 28

Category: 6th TPRM Masterclass

19. Per the 2026 AI Omnibus timing referenced in the masterclass, when do the EU AI Act's Annex III high-risk rules and Annex I product-linked high-risk rules respectively begin to apply?

20 / 28

Category: 6th TPRM Masterclass

20. Under “IP, indemnities and liability,” who retains all rights in Customer Data and other inputs supplied by or on the Customer's behalf?

21 / 28

Category: 6th TPRM Masterclass

21. Under APRA's CPS 230, how is a “fourth party” expressly defined?

22 / 28

Category: 6th TPRM Masterclass

22. Which four questions does the masterclass propose to keep regulatory mapping from becoming a static list of law names?

23 / 28

Category: 6th TPRM Masterclass

23. What illustrative maximum notification window is suggested for an AI-related or security incident?

24 / 28

Category: 6th TPRM Masterclass

24. In the “Dependencies behind an AI service”, which layer most directly affects availability and location of the service?

25 / 28

Category: 6th TPRM Masterclass

25. In FTC v. Rite Aid Corporation, what restriction did the stipulated order impose?

26 / 28

Category: 6th TPRM Masterclass

26. Who is defined as a “Data provider”?

27 / 28

Category: 6th TPRM Masterclass

27. Which four functions does the NIST AI Risk Management Framework organize around, as cited in the masterclass?

28 / 28

Category: 4TPRMMasterclass

How would you rate the overall experience of the event?

  • 28. Highly insightful and engaging
  • Informative and valuable
  • Average / satisfactory
  • Lengthy but useful
  • Too long and less engaging
  • Not relevant / could be improved

Your score is

0%

Exit

5th Masterclass by International TPRM Alliance

0%
11

5th-TPRM Masterclass

5th TPRM Masterclass

Please enter your full name, email address and location for certificate/score-generations! You will receive a certificate only if you score above 70%.

1 / 18

Category: 5th-TPRM Masterclass

1. A CISO believes: 'The Statement of Applicability (SoA) is a one-time document that is only submitted during the initial CORF onboarding and does not need to be updated unless the Central Bank of Kuwait issues a formal audit notice.' What is the actual regulatory requirement?

2 / 18

Category: 5th-TPRM Masterclass

2. A bank is mapping out its implementation lifecycle under CORF and aims to move from the 'Compliance and Maturity Assessment' step to 'CORF Baselines Implementation and Maturity Uplifting,' what intermediate step must be completed?

3 / 18

Category: 4TPRMMasterclass

3. Please share your feedback on the event

  • What did you find most valuable?
  • What could be improved?
  • Any suggestions for future sessions?

4 / 18

Category: 5th-TPRM Masterclass

4. A bank is filling out its Inherent Risk Profiling template. The IT Director asserts: 'We should implement compensating controls first to lower our risk inputs in the profiling sheet, which will lower our assigned Supervisory Tier.' Why is this approach incorrect under CORF?

5 / 18

Category: 4TPRMMasterclass

Which topics would you like to see covered in future roundtables or masterclasses?
e.g.,

  • 5. Third-Party Cyber Risk & Continuous Monitoring
  • AI Risk in Vendor Ecosystems
  • Cloud & SaaS Risk Management
  • Regulatory Compliance (e.g., outsourcing, data protection)
  • Fourth-Party / Concentration Risk
  • Incident & Breach Management involving vendors
  • Other (please specify): __________

6 / 18

Category: 5th-TPRM Masterclass

6. During vendor offboarding, a bank is finalizing its disengagement process. According to the CORF TPRM Exit Strategy domain, which of the following is a key requirement for a structured, secure exit process?

7 / 18

Category: 5th-TPRM Masterclass

7. A local bank is conducting its annual Cyber and Operational Resilience self-assessment. To ensure a standardized, objective evaluation, the bank must apply the 'dual-layered assessment methodology' defined in the CORF Toolkit. What are the two layers evaluated?

8 / 18

Category: 5th-TPRM Masterclass

IT Project Lead argues that: 'IT DRP and BCP are technical documents managed entirely within IT and 8. do not need to be aligned with business-defined recovery metrics like Maximum Tolerable Period of Disruption (MTPD) or RTO'. Under CORF Operational Resilience, what is the flaw in this statement?

9 / 18

Category: 5th-TPRM Masterclass

9. A critical third-party technology vendor hosting a bank's main mobile application experiences a major ransomware attack, causing service disruption. Under the CORF TPRM Baselines, how should the bank's resilience BCP/DR plans have accounted for this?

10 / 18

Category: 4TPRMMasterclass

How would you rate the overall experience of the event?

  • 10. Highly insightful and engaging
  • Informative and valuable
  • Average / satisfactory
  • Lengthy but useful
  • Too long and less engaging
  • Not relevant / could be improved

11 / 18

Category: 5th-TPRM Masterclass

11. A major Bank’s Board of Directors asks the CISO to explain the core strategic shift of the new Cyber and Operational Resilience Framework (CORF). Which of the following best describes this shift?

12 / 18

Category: 5th-TPRM Masterclass

12. Under the TPRM Data Protection and Confidentiality domain - a bank utilizes advanced threat modeling, real-time risk indicators and AI/ML models to dynamically adapt to business needs. What CORF maturity level does this bank demonstrate?

13 / 18

Category: 5th-TPRM Masterclass

13. A Bank’s CISO decides that because the bank does not operate a neobank brand, the entire Emerging Technologies domain is 'Not Applicable' and plans to submit the SoA. What are the rules regarding such exclusions?

14 / 18

Category: 5th-TPRM Masterclass

14. An auditor is assessing a bank's TPRM Business Continuity and Disaster Recovery domain. The bank has comprehensive documentation and regularly reviews its business impact analysis (BIA) to ensure alignment with regulations, but its processes are not yet automated or centralized. What maturity level does this represent?

15 / 18

Category: 5th-TPRM Masterclass

15. A bank's IT department argues that since they have robust firewalls and encryption, they have achieved 'operational resilience' for their payment systems. Why is this perspective incomplete under the CORF?

16 / 18

Category: 5th-TPRM Masterclass

16. During an audit, an auditor notes that a bank has implemented several advanced threat detection systems but lacks a documented process to resume normal operations after an incident is resolved. Which domain or baseline does this gap violate?

17 / 18

Category: 5th-TPRM Masterclass

17. Under the CORF Objectives, which of the following is NOT one of the four main objectives depicted in the framework's core design?

18 / 18

Category: 5th-TPRM Masterclass

18. A Bank’s Executive management claims: 'If we outsource our IT administrative support and database management to an ISO 27001-certified third-party service provider, the bank's Board and management are no longer accountable for the cybersecurity and operational resilience risks of those systems.' How does CORF address this?

Your score is

0%

Exit

3rd TPRM Master Class by International TPRM Alliance

0%
5

The quiz has expired!

2nd TPRM Master Class by International TPRM Alliance

0%
7

The quiz has expired!

1st TPRM Master Class by International TPRM Alliance

0%
16

The quiz has expired!

International TPRM Alliance – 17th TPRM Roundtable 2026 – Post Summit Quiz

0%
14

You have 20 mins to complete this QUIZ! Wish you all the best!

Time is UP!


RTInternationalTPRMAlliance

17th TPRM Roundtable 2026

Please enter your full name, email address and location for certificate/score-generations! You will receive a certificate only if you score above 70%.

1 / 28

Category: 25th April 2026 session quiz

1. Why is cyber risk increasingly classified as a geopolitical issue?

2 / 28

Category: 25th April 2026 session quiz

2. What is the primary impact of regulatory fragmentation across regions?

3 / 28

Category: 4TPRMMasterclass

How would you rate the overall experience of the event?

  • 3. Highly insightful and engaging
  • Informative and valuable
  • Average / satisfactory
  • Lengthy but useful
  • Too long and less engaging
  • Not relevant / could be improved

4 / 28

Category: 25th April 2026 session quiz

4. What is the most immediate impact of sanctions on third-party relationships?

5 / 28

Category: 25th April 2026 session quiz

5. Sanctions on a vendor’s operating country primarily lead to:

6 / 28

Category: 25th April 2026 session quiz

6. Why might vendor diversification fail during geopolitical disruption?

7 / 28

Category: 25th April 2026 session quiz

7. What defines cloud concentration risk in a geopolitical context?

8 / 28

Category: 25th April 2026 session quiz

8. What is a key trade-off in geopolitical risk management?

9 / 28

Category: 25th April 2026 session quiz

9. Which is the most direct geopolitical risk affecting global supply chains?

10 / 28

Category: 4TPRMMasterclass

10. Please share your feedback on the event

  • What did you find most valuable?
  • What could be improved?
  • Any suggestions for future sessions?

11 / 28

Category: 25th April 2026 session quiz

11. Why do data localization laws elevate geopolitical risk?

12 / 28

Category: 25th April 2026 session quiz

12. How are “critical vendors” being redefined in geopolitical contexts?

13 / 28

Category: 25th April 2026 session quiz

13. Which scenario best reflects cyber being used as a geopolitical instrument?

14 / 28

Category: 25th April 2026 session quiz

14. What distinguishes resilience from compliance in a geopolitical context?

15 / 28

Category: 25th April 2026 session quiz

15. What is the most strategic immediate action for a CISO?

16 / 28

Category: 25th April 2026 session quiz

16. What is the core geopolitical concern related to cloud adoption?

17 / 28

Category: 25th April 2026 session quiz

17. How do geopolitical tensions reshape enterprise cybersecurity strategies most directly?

18 / 28

Category: 25th April 2026 session quiz

18. What primarily drives systemic vendor dependency risk in a geopolitical disruption?

19 / 28

Category: 25th April 2026 session quiz

19. What is the key governance gap in TPRM today?

20 / 28

Category: 25th April 2026 session quiz

20. Why is continuous monitoring critical in geopolitical environments?

21 / 28

Category: 25th April 2026 session quiz

21. Which scenario best illustrates the innovation vs sovereignty trade-off?

22 / 28

Category: 25th April 2026 session quiz

22. What is the most underestimated geopolitical risk in supply chains?

23 / 28

Category: 25th April 2026 session quiz

23. What is the evolving role of boards in geopolitical risk management?

24 / 28

Category: 25th April 2026 session quiz

24. Multiple SaaS vendors hosted in the same region create what risk?

25 / 28

Category: 4TPRMMasterclass

Which topics would you like to see covered in future roundtables or masterclasses?
e.g.,

  • 25. Third-Party Cyber Risk & Continuous Monitoring
  • AI Risk in Vendor Ecosystems
  • Cloud & SaaS Risk Management
  • Regulatory Compliance (e.g., outsourcing, data protection)
  • Fourth-Party / Concentration Risk
  • Incident & Breach Management involving vendors
  • Other (please specify): __________

(From a geopolitical risk standpoint only)

26 / 28

Category: 25th April 2026 session quiz

26. Why do nth-party risks significantly increase geopolitical exposure?

27 / 28

Category: 25th April 2026 session quiz

27. Full compliance but failure to detect geopolitical cyber threats indicates:

28 / 28

Category: 25th April 2026 session quiz

28. What is the most effective resilience approach against geopolitical shocks?

Your score is

0%

Exit

International TPRM Alliance – 16th TPRM Roundtable 2025 – Post Summit Quiz

0%
31

The quiz has expired!

International TPRM Alliance – 14th TPRM Roundtable 2025 – Post Summit Quiz

0%
17

The quiz has expired!

International TPRM Alliance – 13th TPRM Roundtable 2025 – Post Summit Quiz

0%
20

The quiz has expired!

International TPRM Alliance – 12th TPRM Roundtable 2025 – Post Summit Quiz

0%
20

The quiz has expired!