FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A bank plans to outsource its payment-processing function to a vendor that itself relies on a subcontractor in another jurisdiction. Which regulatory expectation is most relevant to the bank's due diligence and ongoing oversight?
The bank should identify and manage risks from the vendor's subcontractors, using contract terms such as notification, approval and audit and access rights. Lack of a direct contract does not remove the bank's responsibility, and a blanket ban or financials-only review is not what supervisors expect.
- AThe bank should understand and manage risks arising from the vendor's subcontracting (fourth-party) chain and retain audit and access rightsCorrect
- BSubcontractor risk is outside the bank's scope because no direct contract exists
- COnly the vendor's financial statements need review, not its subcontractors
- DThe bank should prohibit all subcontracting regardless of materiality
Explanation
Supervisors expect banks to assess concentration and dependencies through subcontracting and to secure contractual rights over the chain, such as notification, approval and audit access. Ignoring fourth parties leaves hidden risk. A blanket prohibition is not required and reviewing financials alone is insufficient.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- Before signing a contract with a prospective provider of loan-servicing, which activity should a bank's third-party risk framework place fir…
- A mid-sized bank relies on a single cloud provider to host its payment processing platform. The provider suffers a multi-day outage, and the…
- A bank's vendor risk team discovers that three of its critical service providers, each assessed as independent, all rely on the same subcont…
- A bank discovers that its critical vendor outsources part of the service to a subcontractor, which then fails. The bank had only assessed th…
- A bank wants to reduce the risk that a single cloud provider outage disrupts a critical service with a short impact tolerance. Which action …
- A bank's cloud vendor contract states that the vendor is responsible for the security of the cloud infrastructure, while the bank configures…