Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

A bank's critical service is supplied by a vendor which in turn subcontracts its data hosting to a fourth party. The vendor suffers a failure traced to the fourth party. Which action would best have mitigated this type of exposure?

The best mitigation is mapping the whole supply chain, including subcontractors, and securing contractual visibility and flow-down of control requirements. This lets the bank see and manage fourth-party dependencies instead of relying on the vendor's unverified assurances or financial strength alone.

  1. AMapping the full supply chain, including subcontractors, and requiring contractual visibility and flow-down of controlsCorrect
  2. BReviewing only the vendor's financial statements annually
  3. CIncreasing the vendor's contractual fees to build in a risk premium
  4. DRelying on the vendor's own assurance that subcontractors are adequate

Explanation

Fourth-party risk is managed by mapping dependencies and ensuring contracts give notification, audit rights and flow-down of requirements to subcontractors. Financial review or fees do not reveal operational dependencies, and mere vendor assurance lacks independent verification.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions