FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A bank discovers that business units have each signed vendor contracts independently, and no one can state how many critical third parties the bank uses. Which governance control would most directly address this weakness?
A centralised, complete inventory of third-party arrangements, with each classified by criticality, is the right control. It gives the bank visibility over who its vendors are and which matter most, enabling risk-based oversight. Capital buffers or credit-rating requirements do not solve the lack of information.
- AIncreasing the bank's regulatory capital buffer
- BMaintaining a centralised, complete inventory of third-party arrangements with a criticality classificationCorrect
- CRequiring each vendor to hold a higher credit rating
- DMoving all vendor contracts to a single provider
Explanation
The problem is lack of visibility. A centralised inventory with criticality tiering lets the bank apply proportionate due diligence and monitoring. Capital or ratings do not fix missing information, and consolidating to one provider would increase concentration risk.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A bank's board wants to reduce cloud concentration risk for a critical payment service. The service must resume within 2 hours of a provider…
- A bank's vendor contract for a customer-data hosting service contains a service level agreement (SLA). Which contract clause would most dire…
- After a vendor failure disrupts a bank's customer onboarding service, the board asks how operational resilience differs from traditional ope…
- Following a third-party outage, a bank reviews its exit planning for a critical outsourced service. Which element is most important for the …
- Which statement best describes the purpose of pre-contract due diligence on a prospective critical vendor?
- A bank's board is reviewing its third-party risk management framework. Which responsibility is most appropriately retained by the board rath…