Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

A bank's vendor, which processes card transactions, subcontracts its data-center hosting to another firm that the bank has no contract with. In third-party risk terminology, the hosting firm is best described as a:

The hosting firm is a fourth party, a subcontractor of the bank's direct vendor. Since the bank remains accountable for the outsourced service, it should require disclosure of subcontractors and contractual flow-down of controls, audit rights and incident notification through the vendor.

  1. AFourth party, and the bank should require visibility and flow-down controls over it through the vendorCorrect
  2. BCompetitor, which falls outside the bank's risk framework
  3. CAffiliate, so the bank's own policies apply directly
  4. DRegulator-approved utility, so no due diligence is needed

Explanation

A subcontractor of a bank's direct vendor is a fourth party. The bank remains accountable for outsourced activities, so it should require the vendor to disclose subcontractors and flow down controls, audit rights and notification duties. Regulatory approval of a utility is not assumed here.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions