FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A bank's critical service runs in Region 1 of a cloud provider. The bank's resilience team proposes adding a second availability zone in the same region, with the same provider. Regulators ask whether this addresses concentration and exit risk. Which assessment is most appropriate?
Adding a second zone helps against a single data-center failure but does not remove dependence on the same provider and region. A tested exit plan or multi-provider or multi-region strategy is still needed, because accountability for resilience stays with the bank.
- AIt mitigates single-data-center failure but leaves provider-level and region-level dependency, so a tested exit or multi-provider strategy is still neededCorrect
- BIt eliminates concentration risk because data is now duplicated
- CIt increases concentration risk beyond any prior level and should be avoided
- DIt is irrelevant because the shared responsibility model transfers all resilience duties to the provider
Explanation
A second zone improves local redundancy, but the same provider, control plane and region mean common failure modes remain. Duplication does not remove provider dependency. The shared responsibility model does not transfer accountability for resilience to the provider, so exit plans and testing remain necessary.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A regional bank plans to outsource its card-processing operations to a vendor. Which activity should the bank complete first in the third-pa…
- A bank's risk team is classifying its vendors. Vendor X supplies office stationery. Vendor Y hosts the bank's real-time payments platform, w…
- A bank's vendor contract for a customer-data hosting service contains a service level agreement (SLA). Which contract clause would most dire…
- After a vendor failure disrupts a bank's customer onboarding service, the board asks how operational resilience differs from traditional ope…
- Which statement best describes the purpose of pre-contract due diligence on a prospective critical vendor?
- A bank's board is reviewing its third-party risk management framework. Which responsibility is most appropriately retained by the board rath…