Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

A bank discovers that business units have each signed vendor contracts independently, and no one can state how many critical third parties the bank uses. Which governance control would most directly address this weakness?

A centralised, complete inventory of third-party arrangements, with each classified by criticality, is the right control. It gives the bank visibility over who its vendors are and which matter most, enabling risk-based oversight. Capital buffers or credit-rating requirements do not solve the lack of information.

  1. AIncreasing the bank's regulatory capital buffer
  2. BMaintaining a centralised, complete inventory of third-party arrangements with a criticality classificationCorrect
  3. CRequiring each vendor to hold a higher credit rating
  4. DMoving all vendor contracts to a single provider

Explanation

The problem is lack of visibility. A centralised inventory with criticality tiering lets the bank apply proportionate due diligence and monitoring. Capital or ratings do not fix missing information, and consolidating to one provider would increase concentration risk.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions