A. Compliance is only one category of risk; the primary objective is to understand the full spectrum of risks (e.g., operational, financial, reputational), not just regulatory adherence.
C. Using assessment findings for price negotiation is a secondary, commercial benefit, not the fundamental risk management purpose of the assessment.
D. An organization can never transfer all risk or accountability. The ultimate responsibility for managing risk and protecting assets remains with the outsourcing organization.
References
1. The Santa Fe Group, Shared Assessments Program, "Certified Third Party Risk Professional (CTPRP) Body of Knowledge."
Reference: Domain 3: The Third Party Risk Management Lifecycle, Section on Risk Assessment. This section details that the core purpose of the assessment phase is to gather information to identify and analyze risks posed by the third party. The outcome is a clear understanding of the vendor's control environment and its potential impact on the outsourcer, which directly supports informed decision-making.
2. The Santa Fe Group, Shared Assessments, "A-Z of Third Party Risk Management: A Pocket Guide."
Reference: Definition of "Risk Assessment," page 34. The guide defines risk assessment as the "overall process of risk identification, risk analysis, and risk evaluation." This confirms that the primary goal is to identify and understand risk, which aligns directly with the correct answer.
3. NIST Special Publication 800-30, Revision 1, "Guide for Conducting Risk Assessments."
Reference: Section 2.1, "Purpose and Applicability," page 4. While a general cybersecurity standard, its principles are foundational to the CTPRP curriculum. It states, "The purpose of risk assessments is to inform decision makers and support risk responses by identifying... relevant threats... vulnerabilities... impact... and likelihood." This reinforces that the objective is to provide a comprehensive understanding of risk to support decisions.