Skip to content

FRM Exam Part II · Case Study: Third-party Risk Management

Third-Party Risk Management Lifecycle Steps for FRM Part II

Updated 11 October 2026 · Fact-checked

The third-party risk management lifecycle is the set of stages a bank applies to every vendor: planning and due diligence, contracting, ongoing monitoring, performance review, and exit planning. Risk and criticality drive the depth of work at each stage. To solve exam questions, identify the stage, then pick the control that fits it.

Understand Third-Party Risk Management Lifecycle

A bank that outsources a function keeps the accountability for it. The vendor does the work, but the bank still answers to customers and supervisors. The lifecycle exists so that this accountability is managed from the first idea of outsourcing to the day the relationship ends.

The lifecycle has five stages you should know in order. Due diligence checks whether the vendor can do the job safely before any commitment. Contracting turns the findings into enforceable terms. Ongoing monitoring tracks the vendor while the service runs. Performance review compares results with agreed standards and decides whether to continue, fix or end. Exit planning prepares for termination or vendor failure, and ideally is designed before the contract is signed.

The key idea is proportionality. A critical or material service, such as payment processing or core cloud hosting, gets deep due diligence, tight contract terms, frequent monitoring and a tested exit plan. A low-risk service, such as office supplies, gets light treatment. Criticality is usually judged by the impact on customers, financial stability and operations if the vendor fails, and by how hard the vendor is to replace.

Due diligence covers financial strength, operational capability, information security, business continuity, compliance and legal standing, reputation, use of subcontractors (fourth parties) and concentration. Contracts then set service levels, audit and access rights for the bank and its supervisors, data ownership and confidentiality, incident notification, subcontracting limits, business continuity duties, termination rights and exit assistance.

The board and senior management own the framework. The business line owns the relationship day to day. Risk and compliance functions provide oversight and challenge, and internal audit gives independent assurance. Exam questions usually describe a bank situation and ask which stage failed or which action is best next.

Key formulas to remember

Lifecycle order
Due diligence → Contracting → Ongoing monitoring → Performance review → Exit planning
Exit planning should begin at the planning and contracting stages, not when the relationship is already failing.
Proportionality rule
Depth of control ∝ criticality and risk of the service
Critical services get deeper diligence, tighter terms, more frequent monitoring and tested exit plans.
Accountability rule
Outsourcing transfers the activity, not the accountability
The bank and its board remain responsible to customers and supervisors.
Service level check
Actual performance vs SLA target → breach, escalation, remediation or exit
Use agreed key performance and key risk indicators, not impressions.

How to solve Third-Party Risk Management Lifecycle questions

Use this method for any lifecycle question, whether it is a scenario, a ranking or a best-next-action item.

  1. 1Identify the lifecycle stage described in the scenario: before signing, drafting terms, service running, periodic assessment or ending.
  2. 2Judge the criticality of the service: customer impact, substitutability, data sensitivity and concentration.
  3. 3Match the stage to its core controls: financial, security and resilience checks for diligence; audit rights and SLAs for contracting; indicators and incident tracking for monitoring; scorecards for review; tested plans for exit.
  4. 4Look for the gap in the scenario, such as no audit right, no subcontractor visibility, no exit plan or stale diligence.
  5. 5Choose the answer that fixes the gap at the right stage and is proportionate to the risk.
  6. 6Reject options that shift accountability to the vendor, or that wait for a failure before acting.
  7. 7Check the answer against the board and three lines of defense roles before finalizing.

Quickest way: Stage-then-gap shortcut

When to use it: Use it on scenario items when time is short and options look similar.

  1. Name the stage in five seconds.
  2. Ask: what would a supervisor say is missing here?
  3. Pick the option that adds that missing control at that stage.
  4. Eliminate options that are too late, such as exit steps proposed only after failure, or that ignore criticality.

Common mistakes in Third-Party Risk Management Lifecycle

  • Believing outsourcing transfers risk and responsibility to the vendor

    The contract assigns the task, so it feels like the risk moved too.

    Fix: Remember that the bank stays accountable. Contracts can allocate cost and liability, but not regulatory responsibility.

  • Treating due diligence as a one-time event

    It is listed first, so students assume it ends at onboarding.

    Fix: Diligence is refreshed periodically and on trigger events, with frequency based on criticality.

  • Leaving exit planning until the relationship goes wrong

    Exit is the last stage in the list.

    Fix: Plan exit at the start. Contract terms and a transition plan must exist before problems arise, and critical exits should be tested.

  • Applying the same controls to every vendor

    Students prefer a single uniform checklist.

    Fix: Tier vendors by criticality and scale the depth and frequency of work accordingly.

  • Ignoring fourth parties and concentration

    Attention stays on the direct contract.

    Fix: Require visibility and approval of subcontractors, and assess whether many services rely on the same provider.

  • Confusing monitoring with performance review

    Both involve checking the vendor.

    Fix: Monitoring is continuous tracking of indicators and incidents. Performance review is a periodic assessment against SLAs that leads to a decision.

Worked examples

Example 1

A bank signs a five-year contract with a cloud provider to host its core payments platform. The contract has uptime targets but no audit rights for the bank or its supervisor, and no exit assistance clause. Which lifecycle stage failed, and what is the best fix?

Show the solution
  1. The scenario describes contract terms, so the stage is contracting.
  2. The service is core payments hosting, so it is critical and needs strong terms.
  3. The gaps are missing audit and access rights and missing exit assistance.
  4. The fix is to renegotiate to add audit and access rights for the bank and supervisors, and exit assistance covering data return and transition support.
  5. Also tie the exit clause to a documented exit plan, since the service is hard to replace.

Answer: Contracting failed. Add audit and supervisory access rights and exit assistance terms, and back them with a tested exit plan.

Example 2

A bank's vendor of customer call-centre services repeatedly misses its response-time SLA over three quarters. The vendor's financial position has also weakened. The service is moderately critical. What should the bank do?

Show the solution
  1. Repeated SLA misses found over time point to ongoing monitoring and performance review.
  2. Document the breaches against the agreed indicators and escalate to senior management and the vendor.
  3. Request a remediation plan with deadlines, and refresh financial due diligence because the vendor's condition has changed.
  4. Review the exit plan and identify alternative providers, since failure is now more likely.
  5. If remediation fails, use termination rights and execute the transition.

Answer: Escalate and require a remediation plan, refresh due diligence, and prepare to execute the exit plan if performance does not recover.

Exam tips

  • Always name the lifecycle stage first. Most wrong options are right actions at the wrong stage.
  • Watch for the words critical or material. They signal deeper controls and tested exit plans.
  • Reject any option that says risk or accountability moves to the vendor.
  • Look for hidden fourth-party or concentration issues in cloud and ICT scenarios.
  • Prefer proactive, documented actions such as pre-agreed exit plans over reactive fixes after failure.

Practice questions from Case Study: Third-party Risk Management

Third-Party Risk Management Lifecycle in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Third-Party Risk Management Lifecycle: frequently asked questions

What are the stages of the third-party risk management lifecycle?

The usual stages are due diligence, contracting, ongoing monitoring, performance review and exit planning. Some frameworks add an initial planning or risk assessment step. The depth of each stage depends on how critical the vendor is.

What does vendor due diligence cover for a bank?

It covers the vendor's financial strength, operational capacity, information security, business continuity, compliance, legal standing, reputation, subcontractors and concentration. The bank scales the work to the criticality of the service.

How do banks monitor third parties on an ongoing basis?

They track SLAs and key risk indicators, review incidents, check financial and security reports, and run periodic reassessments. Critical vendors get more frequent and deeper monitoring.

What should an exit strategy for an outsourcing contract include?

It should cover termination triggers, data return and deletion, transition support, alternative providers or in-house options, and tested plans for sudden vendor failure. It should be agreed before the contract goes live.