Skip to content

FRM Part II · FRM Exam Part II · Guidance on Managing Outsourcing Risk

A bank rates its outsourced activities by criticality. Its card-authorization service (provider A) would cause severe customer and regulatory impact if disrupted for more than 2 hours. Its internal newsletter printing (provider B) has negligible impact. Which approach to due diligence and ongoing monitoring is MOST appropriate?

The bank should scale effort to criticality: deeper due diligence, continuity testing, independent assessment and frequent monitoring for the card-authorization provider, and lighter-touch oversight for the newsletter printer. Applying equal or reversed intensity would misallocate resources relative to risk.

  1. AIdentical depth for both to ensure consistency
  2. BGreater depth for A, including on-site or independent assessments of resilience, business continuity testing and frequent monitoring; lighter-touch for BCorrect
  3. CGreater depth for B because lower-risk providers are less mature
  4. DRely on provider self-certification for A and full audits for B

Explanation

Guidance calls for oversight commensurate with risk and criticality. The critical authorization service warrants deeper review of resilience and continuity and tighter monitoring, while the low-impact printing service merits proportionate effort. The inverse approaches misallocate scarce resources.

Did you get it right without looking?

One question tells you little. A timed set on Guidance on Managing Outsourcing Risk shows your real accuracy, how long you take and where you lose marks.

More Guidance on Managing Outsourcing Risk questions