FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A bank assesses 10 critical applications. Cloud Provider A hosts 4, Provider B hosts 3, Provider C hosts 2 and Provider D hosts 1. Using the Herfindahl-Hirschman Index on shares of applications hosted (shares as decimals), what is the HHI, and how does it compare with the minimum possible for 4 providers?
The HHI is 0.30, from 0.16 + 0.09 + 0.04 + 0.01. The minimum for four providers is 0.25 when each hosts an equal share, so the bank's portfolio is somewhat more concentrated than an evenly spread one.
- A0.30, which is above the minimum of 0.25Correct
- B0.30, which is below the minimum of 0.25
- C0.16, which is above the minimum of 0.25
- D0.40, which is the minimum possible
Explanation
Shares are 0.4, 0.3, 0.2, 0.1. Squares: 0.16+0.09+0.04+0.01=0.30. With 4 providers the minimum HHI is 4×0.25²=0.25 at equal shares, so 0.30 shows moderate additional concentration. The 0.16 option only squares the largest share.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A bank has five critical services. Service dependency mapping shows: Provider A supports 3 services, Provider B supports 2 services, and Pro…
- A bank is onboarding a cloud analytics vendor that will process confidential customer data and whose failure would halt daily risk reporting…
- A bank's board wants to reduce cloud concentration risk for a critical payment service. The service must resume within 2 hours of a provider…
- A bank maps the dependencies of its payments service and finds that three apparently independent vendors all run on the same underlying clou…
- A bank classifies vendors by inherent risk score = impact (1-5) x likelihood (1-5). Vendor A: impact 4, likelihood 3. Vendor B: impact 5, li…
- A bank is preparing to outsource its payment-processing platform to an external vendor. Before signing the contract, the risk team wants an …