Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

A bank plans to outsource its payment-processing function to a vendor that itself relies on a subcontractor in another jurisdiction. Which regulatory expectation is most relevant to the bank's due diligence and ongoing oversight?

The bank should identify and manage risks from the vendor's subcontractors, using contract terms such as notification, approval and audit and access rights. Lack of a direct contract does not remove the bank's responsibility, and a blanket ban or financials-only review is not what supervisors expect.

  1. AThe bank should understand and manage risks arising from the vendor's subcontracting (fourth-party) chain and retain audit and access rightsCorrect
  2. BSubcontractor risk is outside the bank's scope because no direct contract exists
  3. COnly the vendor's financial statements need review, not its subcontractors
  4. DThe bank should prohibit all subcontracting regardless of materiality

Explanation

Supervisors expect banks to assess concentration and dependencies through subcontracting and to secure contractual rights over the chain, such as notification, approval and audit access. Ignoring fourth parties leaves hidden risk. A blanket prohibition is not required and reviewing financials alone is insufficient.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions