FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A bank's second line of defense reviews its third-party risk management. Which arrangement best aligns with the three-lines model for outsourcing governance?
Business units, as the first line, own and manage vendor risks; the risk and compliance function, as the second line, sets the framework and challenges; internal audit, as the third line, provides independent assurance. This preserves independence and clear ownership across outsourcing governance.
- ABusiness units own and manage the vendor relationship risks, the risk/compliance function sets the framework and challenges, and internal audit independently assesses the frameworkCorrect
- BInternal audit selects vendors and monitors their performance daily
- CThe risk function owns each vendor relationship and the business units provide independent assurance
- DBusiness units both manage vendor risks and independently audit them to save cost
Explanation
In the three-lines model the first line owns and manages risk, the second line sets policy and provides oversight and challenge, and the third line provides independent assurance. Other options give audit operational duties or remove independence.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A bank is onboarding a cloud analytics vendor that will process confidential customer data and whose failure would halt daily risk reporting…
- During ongoing monitoring, a bank notes that a critical cloud provider has begun subcontracting its data-hosting to a fourth party in anothe…
- A bank maps the dependencies of its payments service and finds that three apparently independent vendors all run on the same underlying clou…
- A bank's risk team is classifying its vendors. Vendor X supplies office stationery. Vendor Y hosts the bank's real-time payments platform, w…
- A bank classifies vendors by inherent risk score = impact (1-5) x likelihood (1-5). Vendor A: impact 4, likelihood 3. Vendor B: impact 5, li…
- A bank is preparing to outsource its payment-processing platform to an external vendor. Before signing the contract, the risk team wants an …