FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A bank's critical service is supplied by a vendor which in turn subcontracts its data hosting to a fourth party. The vendor suffers a failure traced to the fourth party. Which action would best have mitigated this type of exposure?
The best mitigation is mapping the whole supply chain, including subcontractors, and securing contractual visibility and flow-down of control requirements. This lets the bank see and manage fourth-party dependencies instead of relying on the vendor's unverified assurances or financial strength alone.
- AMapping the full supply chain, including subcontractors, and requiring contractual visibility and flow-down of controlsCorrect
- BReviewing only the vendor's financial statements annually
- CIncreasing the vendor's contractual fees to build in a risk premium
- DRelying on the vendor's own assurance that subcontractors are adequate
Explanation
Fourth-party risk is managed by mapping dependencies and ensuring contracts give notification, audit rights and flow-down of requirements to subcontractors. Financial review or fees do not reveal operational dependencies, and mere vendor assurance lacks independent verification.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A bank classifies vendors by criticality using a score equal to impact (1-5) multiplied by substitutability difficulty (1-5), and applies en…
- A mid-sized bank outsources its customer call-centre operations to a vendor. A senior manager argues that because the vendor performs the ac…
- A bank is negotiating a contract with a critical outsourced service provider. Which clause most directly allows the bank and its regulator t…
- A mid-sized bank plans to outsource its loan-servicing platform to a cloud provider. Under supervisory guidance on managing outsourcing risk…
- A regional bank moves its customer-complaint handling to an external call-centre provider. Under widely accepted third-party risk principles…
- A bank's board is reviewing its third-party risk framework after a vendor failure. Which of the following best describes an appropriate divi…