Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

A bank's contract with a critical vendor expires in 6 months and the vendor has had repeated service-level breaches. Which action best reflects sound practice at the termination or renewal stage of the lifecycle?

The bank should use its monitoring evidence to decide on renewal or exit, while testing its exit plan, identifying alternative providers and ensuring secure data return or destruction. Automatic renewal ignores repeated breaches, and monitoring should not stop until the transition is complete.

  1. AAuto-renew the contract to avoid disruption and review later
  2. BEvaluate monitoring results, test the exit plan and alternative providers, and decide on renewal or transition with data return provisionsCorrect
  3. CStop all monitoring since the relationship is ending
  4. DTransfer the vendor's data to the vendor's other clients for continuity

Explanation

Renewal or exit decisions should draw on performance history, including SLA breaches, and the bank should have a tested exit strategy covering alternative providers and secure return or destruction of data. Auto-renewal ignores the evidence, and monitoring must continue until transition completes.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions