Skip to content

FRM Exam Part II · Case Study: Third-party Risk Management

Third-Party Risk Governance, Roles and Regulatory Expectations

Updated 11 October 2026 · Fact-checked

Third-party risk governance sets who is accountable for outsourced activities. The board approves strategy and risk appetite. Senior management implements the program. The three lines of defense own, oversee and audit the risk. Supervisors expect the bank to stay fully responsible for outsourced services, whatever the contract says.

Understand Governance, Roles and Regulatory Expectations

Third-party risk is the risk that a vendor, outsourcer or other service provider fails, underperforms or exposes the bank to loss. The key principle is simple: you can outsource a task, but you cannot outsource accountability. The bank stays responsible to customers and supervisors.

Accountability starts at the top. The board sets risk appetite, approves the third-party policy and oversees critical or material arrangements. Senior management turns that policy into a program: inventory, due diligence, contracts, monitoring, reporting and exit plans. Management reports to the board on material or critical providers and on breaches of appetite.

The three lines of defense split the work. The first line is the business unit or relationship owner that uses the provider. It owns the risk day to day, does due diligence and monitors performance. The second line is risk and compliance. It sets the framework, challenges the first line, aggregates exposure and tracks concentration. The third line is internal audit. It gives independent assurance that the framework works. Audit should not run controls it later audits.

Supervisors set common expectations across regimes. These include a risk-based approach, a full inventory, clear identification of critical activities, due diligence before contracting, contracts with audit and access rights, ongoing monitoring, business continuity and exit plans, and notification of material arrangements. US interagency guidance on third-party relationships (OCC, Federal Reserve and FDIC) uses a lifecycle: planning, due diligence, contract negotiation, ongoing monitoring and termination. EBA outsourcing guidelines apply to outsourcing by EU institutions, and DORA is an EU regulation for ICT third-party risk with a register of information and oversight of critical ICT providers. Know the common themes more than the fine detail.

Key formulas to remember

Accountability rule
Outsourcing the activity ≠ outsourcing the responsibility
The bank and its board remain accountable to supervisors and customers.
Lifecycle of US interagency guidance
Planning → Due diligence → Contract negotiation → Ongoing monitoring → Termination
Use this order to place any question in the right stage.
Three lines of defense
1st: own and manage | 2nd: oversee and challenge | 3rd: independent assurance
Audit is the third line; risk and compliance are the second.
Risk-based proportionality
Depth of oversight ∝ criticality and risk of the arrangement
Critical activities get the most board attention, testing and exit planning.

How to solve Governance, Roles and Regulatory Expectations questions

Use this method on any governance or regulatory question about third parties.

  1. 1Identify what the question tests: accountability, a line-of-defense role, a lifecycle stage or a regulatory regime.
  2. 2Ask who is the right owner: board (appetite, policy, critical arrangements), senior management (implementation), or a line of defense.
  3. 3Place the issue in the lifecycle stage: planning, due diligence, contract, monitoring or termination.
  4. 4Check criticality. Critical or material arrangements need stronger controls and board reporting.
  5. 5Apply the principle that accountability stays with the bank, even for subcontractors and fourth parties.
  6. 6Eliminate options that give the board day-to-day tasks, let audit run controls, or let the vendor own the risk.
  7. 7Pick the answer that is risk-based, documented and independent where needed.

Quickest way: Who owns it and where in the lifecycle

When to use it: Short scenario questions with four plausible governance options.

  1. Underline the actor in the question: board, management, business, risk, audit or vendor.
  2. Match the actor: board = oversight and appetite; management = program; 1st = do; 2nd = challenge; 3rd = assure.
  3. Reject any option that moves accountability to the vendor.
  4. Choose the option tied to criticality and independence.

Common mistakes in Governance, Roles and Regulatory Expectations

  • Saying the vendor takes on the regulatory responsibility once a contract is signed.

    Contract language about liability is confused with supervisory accountability.

    Fix: Remember that the bank is always responsible. A contract can allocate costs, not remove the bank's duty.

  • Placing third-party monitoring as the main job of internal audit.

    Audit sounds like oversight.

    Fix: The first line monitors day to day. The second line challenges. Audit gives independent assurance on the whole framework.

  • Giving the board operational tasks such as vendor selection.

    Students confuse oversight with execution.

    Fix: The board approves policy and appetite and oversees critical arrangements. Management selects and manages vendors.

  • Treating all vendors with the same level of oversight.

    Students forget proportionality.

    Fix: Tier vendors by criticality and risk. Critical ones get deeper due diligence, testing and exit plans.

  • Mixing up the EBA guidelines and DORA.

    Both cover outsourcing and ICT providers in the EU.

    Fix: Recall that the EBA guidelines are supervisory guidelines on outsourcing, while DORA is a binding EU regulation on ICT risk, with a register of information and oversight of critical ICT providers.

  • Ignoring fourth parties and subcontractors.

    Focus stays on the direct contract.

    Fix: Expect the bank to understand and control subcontracting chains that support critical services.

Worked examples

Example 1

A bank outsources its payment processing to a cloud provider. After an outage, the CRO says the provider is liable, so the bank has no regulatory exposure. Which statement best reflects supervisory expectations? (A) The CRO is right because the contract transfers liability. (B) The bank remains accountable, and the board should oversee critical arrangements. (C) Internal audit should have prevented the outage. (D) Only the provider's regulator is responsible.

Show the solution
  1. Identify the principle: accountability cannot be outsourced.
  2. Test A: a contract may allocate financial liability but does not remove supervisory responsibility. Reject.
  3. Test C: audit gives assurance and does not run operations. Reject.
  4. Test D: the bank's own supervisor still holds the bank responsible. Reject.
  5. Test B: matches the principle and the board's oversight role for critical services.

Answer: (B)

Example 2

A relationship manager in a business unit performs due diligence on a new vendor and monitors its service levels. The risk function reviews the approach, challenges ratings and reports aggregate vendor concentration. Internal audit later tests whether the framework works. Assign the three lines of defense.

Show the solution
  1. The business unit that owns the relationship and does due diligence and monitoring is the first line.
  2. The risk function that sets the framework, challenges and aggregates concentration is the second line.
  3. Internal audit gives independent assurance, so it is the third line.
  4. Check independence: audit does not run the controls it audits, so the structure is sound.

Answer: First line: business unit. Second line: risk function. Third line: internal audit.

Exam tips

  • Most governance questions test who owns what. Map each actor to its role before reading the options.
  • Look for the words critical or material. They signal stronger board oversight and exit planning.
  • Do not memorise article numbers. Know the themes: inventory, due diligence, contract rights, monitoring, exit and concentration.
  • For EBA versus DORA, remember guidelines on outsourcing versus a regulation with a register and critical ICT provider oversight.
  • Eliminate any option that moves accountability to the vendor.

Practice questions from Case Study: Third-party Risk Management

Governance, Roles and Regulatory Expectations: frequently asked questions

Who is ultimately accountable for third-party risk in a bank?

The bank is accountable, and within it the board and senior management. The board sets appetite and oversees critical arrangements. Management runs the program.

What are the three lines of defense in third-party risk?

The first line is the business owner of the relationship, who manages the risk. The second line is risk and compliance, which sets the framework and challenges. The third line is internal audit, which gives independent assurance.

What does US interagency guidance say about third-party relationships?

It describes a risk-based lifecycle: planning, due diligence, contract negotiation, ongoing monitoring and termination. Banks should scale oversight to the criticality of each relationship. Responsibility stays with the bank.

How do EBA outsourcing guidelines differ from DORA?

The EBA guidelines set supervisory expectations for outsourcing by EU institutions. DORA is an EU regulation on ICT risk that includes a register of ICT third-party arrangements and oversight of critical ICT providers. For the exam, focus on the shared themes and the difference in legal form.