FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A bank's risk team is classifying its vendors. Vendor X supplies office stationery. Vendor Y hosts the bank's real-time payments platform, which cannot be restored by any alternative supplier within 48 hours. Which approach to tiering is most appropriate?
Vendor Y should be classified as critical and given enhanced due diligence, exit planning and continuous monitoring, while stationery vendor X gets lighter oversight. Oversight should be proportionate to the criticality of the service and the difficulty of substituting the provider.
- ATreat both identically to keep the programme simple, with annual on-site audits for each
- BClassify Y as critical, applying enhanced due diligence, exit planning and continuous monitoring, while X receives lighter-touch oversightCorrect
- CClassify X as critical because it has the highest transaction count
- DClassify neither as critical because both are external and therefore outside the bank's control
Explanation
Proportionality requires oversight intensity to reflect criticality and substitutability. Y supports a critical function with no quick alternative, so it warrants enhanced controls and exit planning. Treating both alike wastes resources and dilutes focus on the real risk.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A bank's third-party risk policy requires an exit strategy for critical outsourced services. A regulator reviewing the bank finds that the s…
- A bank's critical service has an impact tolerance of 8 hours. Its vendor contract guarantees recovery within 6 hours, but the vendor depends…
- A bank's second line of defense reviews its third-party risk management. Which arrangement best aligns with the three-lines model for outsou…
- A regional bank relies on a single cloud provider to host its payment processing platform. The provider suffers a multi-day outage, and the …
- A bank notices that several of its critical vendors all rely on the same cloud infrastructure provider. Which risk is this most directly des…
- A mid-sized bank relies on a single cloud provider to host its payments platform, core ledger and customer authentication service. The risk …