FRM Part II · FRM Exam Part II · Risk Mitigation
A bank outsources its loan-servicing platform to a vendor that itself relies on a single cloud provider. The bank's risk committee wants to mitigate the resulting concentration and fourth-party risk. Which action is most effective in addressing the specific weakness?
The most effective action is to require subcontractor disclosure, tested failover to an alternate provider, and exit and step-in provisions. These directly address fourth-party concentration and continuity, whereas indemnities, extra capital or a one-time report only cover financial loss or provide point-in-time assurance.
- ARely on the vendor's contractual indemnity for any losses
- BRequire the vendor to disclose subcontractors, test failover to an alternate provider, and include exit and step-in provisions in the contractCorrect
- CIncrease the bank's operational risk capital buffer only
- DObtain a one-time SOC report at contract signing
Explanation
The weakness is dependence on a single hidden subcontractor. Transparency on fourth parties, tested failover and exit or step-in rights address the concentration directly and preserve resilience. Indemnity and capital address only financial loss, and a one-time report does not provide ongoing assurance.
Did you get it right without looking?
One question tells you little. A timed set on Risk Mitigation shows your real accuracy, how long you take and where you lose marks.
More Risk Mitigation questions
- After a breach investigation, a bank finds that an attacker used stolen credentials of a vendor to move laterally from a low-sensitivity rep…
- During due diligence on a prospective cloud service provider, which finding should most concern a bank's risk committee when the service sup…
- A bank outsources its customer call centre to a vendor under a contract with service-level agreements. After a vendor failure, the bank's cu…
- Which practice best addresses moral hazard that arises once a bank has purchased operational risk insurance?
- A bank's operational risk team classifies a newly adopted control: a network intrusion detection system that raises an alert when unusual ou…
- A bank's security team wants a control that ensures a compromised employee credential cannot, by itself, give an attacker access to the onli…