Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

A bank is onboarding a cloud analytics vendor that will process confidential customer data and whose failure would halt daily risk reporting. Before signing, which action best reflects sound third-party risk assessment practice?

The best practice is to tier the vendor by criticality and data sensitivity and apply due diligence proportionate to that tier. A vendor supporting critical reporting and holding confidential data needs enhanced review before signing, not uniform light-touch checks or delayed diligence.

  1. ARely on the vendor's marketing materials and its low price as evidence of adequate controls
  2. BClassify the vendor by criticality and data sensitivity, then perform due diligence proportionate to that tierCorrect
  3. CApply identical light-touch due diligence to all vendors to keep onboarding consistent
  4. DDefer due diligence until after the first year of service, when performance data is available

Explanation

Sound practice is risk-based: vendors are tiered by criticality and data sensitivity, and the depth of due diligence follows the tier. This vendor supports a critical process and handles confidential data, so it needs enhanced review. Uniform light-touch review under-assesses critical vendors, and deferring diligence until after service starts exposes the bank before controls are verified.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions