FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A bank's vendor risk team discovers that three of its critical service providers, each assessed as independent, all rely on the same subcontracted data-centre operator. This is best described as:
This is fourth-party concentration risk. The three vendors appear independent, but they share one subcontracted data-centre operator, so a single failure there would hit all of them simultaneously and defeat the diversification the bank believed it had.
- AFourth-party concentration riskCorrect
- BInherent counterparty credit risk
- CResidual model risk
- DSettlement risk
Explanation
The shared subcontractor sits beyond the bank's direct contracts, making it a fourth party. Its failure would hit all three vendors together, so apparent diversification is illusory. This is not credit, model or settlement risk.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A bank's vendor, which processes card transactions, subcontracts its data-center hosting to another firm that the bank has no contract with.…
- A bank discovers that business units have each signed vendor contracts independently, and no one can state how many critical third parties t…
- Before onboarding a new critical SaaS vendor, a bank wants to manage the risk that the vendor's own cloud host fails. Which action most dire…
- Following a vendor failure, a bank's review finds its contract lacked exit provisions, audit rights and incident notification timelines. At …
- During due diligence on a cloud provider that will host a critical payments application, a risk manager finds the provider relies on a subco…
- A bank has a critical service with an impact tolerance of 8 hours. During a vendor failure test, detection takes 1.5 hours, the decision to …