FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A bank classifies 40 of its 200 third-party arrangements as critical. Internal audit finds that only 24 of the critical arrangements have a tested exit plan, and that 30 non-critical arrangements also have one. Management says that 27% of all arrangements have tested exit plans, so the framework is adequate. What is the best assessment?
The aggregate of 54 of 200, or 27%, is arithmetically right but misleading. Coverage of critical arrangements is only 24 of 40, or 60%. Supervisory expectations focus exit planning on critical providers, so the low critical coverage is a governance gap despite the blended figure.
- AThe 27% figure is correct (54 of 200) but the more relevant metric is coverage of critical arrangements, which is 60% (24 of 40), indicating a gap against expectationsCorrect
- BThe 27% figure is incorrect because it should be 24 of 200, or 12%
- CCoverage of critical arrangements is 80%, so the framework is adequate
- DExit plans are only required for non-critical arrangements, so 30 of 160 is the relevant metric
Explanation
Total with plans = 24 + 30 = 54; 54/200 = 27%. Critical coverage = 24/40 = 60%. Supervisors expect exit strategies especially for critical arrangements, so the aggregate figure masks a gap. Option B ignores non-critical plans; C and D misstate the data or the requirement.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- Which statement best describes the purpose of pre-contract due diligence on a prospective critical vendor?
- A bank's board is reviewing its third-party risk management framework. Which responsibility is most appropriately retained by the board rath…
- A bank's board wants to reduce cloud concentration risk for a critical payment service. The service must resume within 2 hours of a provider…
- A bank classifies vendors by criticality using a score equal to impact (1-5) multiplied by substitutability difficulty (1-5), and applies en…
- A mid-sized bank outsources its customer call-centre operations to a vendor. A senior manager argues that because the vendor performs the ac…
- A bank's critical service is supplied by a vendor which in turn subcontracts its data hosting to a fourth party. The vendor suffers a failur…