Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

A bank's board is reviewing its third-party risk framework after a vendor failure. Which of the following best describes an appropriate division of responsibilities under sound governance practice?

The board approves the third-party risk appetite and policy and oversees material arrangements, while senior management implements the framework, manages vendors and reports upward. Internal audit gives independent assurance rather than operating controls, and business units do not set policy alone.

  1. AThe board approves the outsourcing risk appetite and policy, while senior management implements it and reports on material arrangementsCorrect
  2. BBusiness units alone set outsourcing policy and report only to the vendor
  3. CSenior management approves the risk appetite while the board manages day-to-day vendor performance
  4. DInternal audit owns and operates the vendor controls to ensure independence

Explanation

Good governance has the board set or approve risk appetite and policy and oversee material arrangements, while senior management implements the framework and reports. Internal audit provides independent assurance and should not own operational controls, which rules out the last option. Having the board run day-to-day vendor performance reverses the roles.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions