FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A mid-sized asset manager is deciding whether to outsource its fund accounting function. Which of the following is the most typical strategic driver for outsourcing such a non-core, process-intensive activity, as opposed to a risk that results from doing so?
The typical driver is access to specialised expertise and economies of scale, letting the firm concentrate on core activities. Outsourcing does not remove operational risk, tends to reduce direct control, and can raise supplier concentration, so those options are not drivers.
- AGaining access to specialised expertise and economies of scale while focusing on core activitiesCorrect
- BEliminating all operational risk associated with the activity
- CReducing concentration risk among suppliers
- DIncreasing the firm's direct control over data and processing
Explanation
Common drivers are cost efficiency, scale, specialist skills, and focus on core business. Outsourcing does not eliminate operational risk; it changes it into third-party risk. It can raise concentration risk and usually reduces direct control, so those options describe consequences or are wrong.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- Following a vendor failure, a bank's review finds its contract lacked exit provisions, audit rights and incident notification timelines. At …
- A regional bank relies on a single cloud provider to host its payment processing platform. The provider suffers a multi-day outage, and the …
- During due diligence on a cloud provider that will host a critical payments application, a risk manager finds the provider relies on a subco…
- A bank has a critical service with an impact tolerance of 8 hours. During a vendor failure test, detection takes 1.5 hours, the decision to …
- A bank's contract with a critical vendor expires in 6 months and the vendor has had repeated service-level breaches. Which action best refle…
- During ongoing monitoring, a bank notes that a critical cloud provider has begun subcontracting its data-hosting to a fourth party in anothe…