Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

A bank's board is reviewing its outsourcing policy. Which element is most consistent with sound practice for managing risk across the third-party lifecycle?

Sound practice is risk-based due diligence before contracting, ongoing monitoring during the relationship, and a documented exit strategy. Controls should be proportionate to criticality, and the bank cannot rely only on vendor self-assessment or occasional reviews at renewal.

  1. ARisk-based due diligence before contracting, followed by ongoing monitoring and a documented exit strategyCorrect
  2. BDue diligence performed only at contract renewal, with monitoring left to the vendor
  3. CApplying identical controls to every vendor regardless of criticality
  4. DRelying solely on the vendor's self-assessment of its controls

Explanation

Sound practice covers the whole lifecycle: risk-based selection and due diligence, contract terms, continuous monitoring, and exit planning. Reliance on vendor self-assessment, uniform controls, or renewal-only checks leaves gaps and ignores proportionality to criticality.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions