Skip to content

FRM Exam Part II · Case Study: Third-party Risk Management

Third-Party Risk Fundamentals and Outsourcing Drivers

Updated 11 October 2026 · Fact-checked

Third-party risk is the chance that a supplier, service provider or other outside party causes loss, disruption or damage to your firm. Outsourcing is one type of third-party relationship, where a firm hands an activity to another party. To answer questions, identify the relationship, the driver, and the risk it creates: operational, concentration or reputational.

Understand Third-Party Risk Fundamentals and Outsourcing Drivers

A third party is any external entity a firm has a business relationship with. This includes vendors, cloud providers, payment processors, data suppliers, brokers, joint-venture partners and group affiliates outside the legal entity. The term is broad.

Outsourcing is narrower. It means a firm uses another party to perform an activity that the firm would otherwise do itself, either now or in the past. Many third-party relationships are not outsourcing. Buying standard office furniture is a third-party purchase, not outsourcing. So all outsourcing is third-party, but not all third-party is outsourcing. Outsourcing is also not the same as delegation of accountability: you can hand over the task, but the board and senior management stay accountable for it.

Firms outsource for several reasons: cost reduction and economies of scale; access to specialist skills or technology they cannot build quickly; flexibility to scale volumes up or down; a wish to focus on core business; and speed to market. Regulators accept these reasons but expect the firm to weigh them against the risks.

The risks fall into three main groups. Operational risk: the provider fails, makes errors, suffers a cyber incident or breaches data, and your service stops. Concentration risk: many functions sit with one provider, or many firms rely on the same provider, so one failure spreads widely. Reputational risk: customers blame you for the provider's poor conduct or outage. Others include compliance, legal, data-privacy and exit risk (difficulty in bringing the activity back or moving it).

The key principle: you can transfer the activity, but you cannot transfer the risk or the responsibility. The firm must still manage, monitor and be able to recover from provider failure.

Key formulas to remember

Scope relationship
Outsourcing ⊂ Third-party relationships
Every outsourcing arrangement is a third-party relationship, but many third-party relationships (e.g. buying standard goods) are not outsourcing.
Accountability rule
Activity can be transferred; accountability cannot
The board and senior management remain accountable for outsourced activities and their risks.
Risk grouping
Third-party risk = operational + concentration + reputational (+ compliance, legal, data, exit)
A classification, not a numerical formula. Use it to label the risk in a scenario.
Concentration test
Concentration exists when one provider supports many critical functions, or many firms depend on one provider
Firm-level and sector-level concentration are different. Both matter.

How to solve Third-Party Risk Fundamentals and Outsourcing Drivers questions

Use this sequence for any scenario or definition question on this topic.

  1. 1Identify the relationship: is it a general third-party link or true outsourcing of an activity the firm could perform itself?
  2. 2Name the driver: cost, expertise, scalability, focus on core business or speed. Check whether the question asks for a benefit or a risk.
  3. 3Judge how critical the activity is. Critical or customer-facing functions need stronger oversight.
  4. 4Classify the risk in the scenario: operational (failure, error, cyber), concentration (single provider or shared dependency), reputational (customer or public reaction), or another type.
  5. 5Check who is accountable. The answer is almost always the firm's board and senior management, not the provider.
  6. 6Pick the control that fits the risk: due diligence, contract terms, monitoring, diversification, exit plan or continuity testing.
  7. 7Eliminate options that claim risk is transferred, or that treat low cost as the only deciding factor.

Quickest way: Driver, Risk, Accountability scan

When to use it: Use when you have about a minute per question and the stem describes a firm using an outside provider.

  1. Underline the activity and the provider in the stem.
  2. Ask: what was the firm trying to gain (the driver)?
  3. Ask: what went wrong or could go wrong (operational, concentration, reputational)?
  4. Choose the answer that keeps accountability with the firm and adds a proportionate control.
  5. Reject absolute answers such as 'eliminates the risk' or 'transfers responsibility'.

Common mistakes in Third-Party Risk Fundamentals and Outsourcing Drivers

  • Treating third-party risk and outsourcing as identical terms.

    Textbooks and regulators use them close together, so they seem interchangeable.

    Fix: Remember third-party is the wider set. Outsourcing is the part where an activity is handed over.

  • Saying outsourcing transfers the risk to the provider.

    A contract and a service level agreement feel like they move the liability.

    Fix: Contracts can allocate some financial loss, but regulatory accountability and customer impact stay with the firm.

  • Confusing concentration risk with simple diversification of vendors.

    Students think using several providers always removes concentration.

    Fix: Check for shared dependencies. Several vendors may use the same cloud platform, so concentration can remain at a deeper level.

  • Naming cost saving as the only driver.

    Cost is the most obvious reason.

    Fix: List the other drivers too: expertise, scalability, flexibility, focus on core activities and speed.

  • Ignoring reputational risk when the failure is the provider's.

    Students focus on operational loss and forget customer perception.

    Fix: Ask who the customer sees. If your brand faces the customer, you bear the reputational damage.

  • Applying the same oversight to every provider.

    Students want one uniform answer.

    Fix: Use a risk-based approach: scale due diligence and monitoring to how critical the activity is.

Worked examples

Example 1

A bank outsources its card payment processing to a single provider to cut costs and gain scalability. The provider suffers a multi-day outage and customers cannot pay. Which statement is most accurate? (A) The risk was transferred to the provider, so the bank has no residual exposure. (B) The bank retains accountability, and the event shows operational, concentration and reputational risk. (C) Only the provider faces reputational risk. (D) The event is a pure market risk loss.

Show the solution
  1. Identify the relationship: card processing is an activity the bank could perform itself, so this is outsourcing.
  2. Drivers given: cost and scalability. These are valid drivers.
  3. Risk type: the outage stops service, which is operational risk. Reliance on a single provider is concentration risk. Customers see the bank's brand, so reputational risk arises.
  4. Accountability: the bank remains accountable despite the contract.
  5. Check options: A is wrong because risk is not transferred. C is wrong because customers blame the bank. D is wrong because no market price moved.

Answer: (B)

Example 2

A risk manager lists outsourcing drivers for a mid-sized bank. Which one is NOT normally a recognised driver? (A) Access to specialist technology. (B) Flexibility to scale volumes. (C) Removing board accountability for the function. (D) Focus on core business.

Show the solution
  1. Recall the accepted drivers: cost, expertise, technology, scalability, focus on core business, speed.
  2. A, B and D match these drivers.
  3. C is not a driver because regulators say accountability cannot be outsourced.
  4. So C is the exception.

Answer: (C)

Exam tips

  • Expect scenario questions where a provider fails. Name the risk type first, then the control.
  • Memorise that accountability stays with the board and senior management. This resolves many options at once.
  • Watch for words like 'eliminates', 'fully transfers' or 'always'. These are usually wrong.
  • Separate firm-level concentration (one provider, many functions) from sector-level concentration (many firms, one provider).
  • Link the activity's criticality to the strength of oversight. Proportionality is a frequent correct answer.

Practice questions from Case Study: Third-party Risk Management

Third-Party Risk Fundamentals and Outsourcing Drivers: frequently asked questions

What is third-party risk in banking?

It is the risk of loss, disruption or reputational harm arising from a bank's dependence on outside parties such as vendors, cloud providers and service firms. It covers operational, concentration, compliance, data and reputational risks.

What is the difference between outsourcing and third-party risk?

Outsourcing is one kind of third-party relationship, where an activity is performed by another party for the firm. Third-party risk is the broader risk from all outside relationships, including purchases and partnerships that are not outsourcing.

Why do banks outsource critical functions despite the risks?

They gain cost efficiency, specialist skills, scalability and more focus on core business. Regulators allow this if the bank manages the risks through due diligence, contracts, monitoring and exit planning.

Can a bank transfer risk to a vendor by contract?

Not fully. A contract can allocate some financial loss, but the bank stays accountable to regulators and customers. Operational and reputational impact still falls on the bank.