Skip to content

FRM Part II · FRM Exam Part II · Guidance on Managing Outsourcing Risk

A bank's risk committee is designing its service provider risk management program. Which element would be MOST consistent with supervisory guidance on the program's core structure?

The program should include risk assessment, due diligence before selecting a provider, careful contract review, and ongoing monitoring, all scaled to the risk and complexity of the outsourced activity. Uniform treatment or after-the-fact due diligence would not meet supervisory expectations.

  1. AA single contract template applied identically to every provider regardless of criticality
  2. BRisk assessments, due diligence in selecting providers, contract review, and ongoing monitoring, with oversight scaled to the activity's risk and complexityCorrect
  3. CDue diligence performed only after contract signing to avoid delaying implementation
  4. DMonitoring limited to annual receipt of the provider's marketing materials

Explanation

Guidance describes a program with risk assessment, provider selection due diligence, contract negotiation, and ongoing oversight, all commensurate with the level of risk and complexity. Uniform templates ignore criticality, and post-signing due diligence defeats the selection purpose.

Did you get it right without looking?

One question tells you little. A timed set on Guidance on Managing Outsourcing Risk shows your real accuracy, how long you take and where you lose marks.

More Guidance on Managing Outsourcing Risk questions