FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A bank's board is reviewing its third-party risk framework after a vendor failure. Which of the following best describes an appropriate division of responsibilities under sound governance practice?
The board approves the third-party risk appetite and policy and oversees material arrangements, while senior management implements the framework, manages vendors and reports upward. Internal audit gives independent assurance rather than operating controls, and business units do not set policy alone.
- AThe board approves the outsourcing risk appetite and policy, while senior management implements it and reports on material arrangementsCorrect
- BBusiness units alone set outsourcing policy and report only to the vendor
- CSenior management approves the risk appetite while the board manages day-to-day vendor performance
- DInternal audit owns and operates the vendor controls to ensure independence
Explanation
Good governance has the board set or approve risk appetite and policy and oversee material arrangements, while senior management implements the framework and reports. Internal audit provides independent assurance and should not own operational controls, which rules out the last option. Having the board run day-to-day vendor performance reverses the roles.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A bank's risk team is classifying its vendors. Vendor X supplies office stationery. Vendor Y hosts the bank's real-time payments platform, w…
- A bank uses a scorecard to rank vendors by residual risk. Inherent risk is scored 1-5 and control effectiveness reduces it by a factor: resi…
- A mid-sized asset manager is deciding whether to outsource its fund accounting function. Which of the following is the most typical strategi…
- A bank sets an impact tolerance of 8 hours maximum disruption for a critical payments service. A scenario test of a vendor failure shows: ve…
- A bank's board is reviewing its third-party risk framework. Which of the following is the most appropriate responsibility for the board itse…
- A bank's critical service runs in Region 1 of a cloud provider. The bank's resilience team proposes adding a second availability zone in the…