FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A bank is negotiating a contract with a critical outsourced service provider. Which clause most directly allows the bank and its regulator to verify the provider's controls independently?
Access and audit rights for the bank, its auditors and supervisors are the clause that enables independent verification of the provider's controls. Liability caps and price escalation are commercial terms, and unrestricted subcontracting weakens visibility into who actually performs the service.
- AA limitation-of-liability cap equal to annual fees
- BAccess and audit rights extending to the bank, its auditors and supervisorsCorrect
- CA price-escalation clause tied to inflation
- DA clause allowing unrestricted subcontracting by the provider
Explanation
Access and audit rights let the bank and supervisors inspect the provider's premises, records and controls, giving independent assurance. A liability cap and price escalation are commercial terms that do not provide verification. Unrestricted subcontracting actually reduces transparency and increases fourth-party risk.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A bank's vendor, which processes card transactions, subcontracts its data-center hosting to another firm that the bank has no contract with.…
- A bank discovers that business units have each signed vendor contracts independently, and no one can state how many critical third parties t…
- Before onboarding a new critical SaaS vendor, a bank wants to manage the risk that the vendor's own cloud host fails. Which action most dire…
- After a vendor failure disrupted its trade settlement service, a bank's board wants to define its operational resilience tolerance for that …
- Following a vendor failure, a bank's review finds its contract lacked exit provisions, audit rights and incident notification timelines. At …
- During due diligence on a cloud provider that will host a critical payments application, a risk manager finds the provider relies on a subco…