FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A bank's vendor, which processes card transactions, subcontracts its data-center hosting to another firm that the bank has no contract with. In third-party risk terminology, the hosting firm is best described as a:
The hosting firm is a fourth party, a subcontractor of the bank's direct vendor. Since the bank remains accountable for the outsourced service, it should require disclosure of subcontractors and contractual flow-down of controls, audit rights and incident notification through the vendor.
- AFourth party, and the bank should require visibility and flow-down controls over it through the vendorCorrect
- BCompetitor, which falls outside the bank's risk framework
- CAffiliate, so the bank's own policies apply directly
- DRegulator-approved utility, so no due diligence is needed
Explanation
A subcontractor of a bank's direct vendor is a fourth party. The bank remains accountable for outsourced activities, so it should require the vendor to disclose subcontractors and flow down controls, audit rights and notification duties. Regulatory approval of a utility is not assumed here.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- During ongoing monitoring, a bank notes that a critical cloud provider has begun subcontracting its data-hosting to a fourth party in anothe…
- A bank discovers that business units have each signed vendor contracts independently, and no one can state how many critical third parties t…
- Before onboarding a new critical SaaS vendor, a bank wants to manage the risk that the vendor's own cloud host fails. Which action most dire…
- A bank's risk team is classifying its vendors. Vendor X supplies office stationery. Vendor Y hosts the bank's real-time payments platform, w…
- Following a vendor failure, a bank's review finds its contract lacked exit provisions, audit rights and incident notification timelines. At …
- During due diligence on a cloud provider that will host a critical payments application, a risk manager finds the provider relies on a subco…