Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

A mid-sized bank signs a contract with a cloud provider to host its core payments platform. A senior manager argues that because the provider is contractually responsible for uptime and security, the bank has transferred accountability for the outsourced activity. Which view is consistent with supervisory expectations on outsourcing and third-party risk?

The bank's board and senior management remain ultimately accountable for outsourced activities. Contracts, SLAs and indemnities can shift financial remedies but not regulatory responsibility, so the bank must still oversee the provider and manage the risks arising from the arrangement, whether the activity is critical or not.

  1. AAccountability transfers to the provider once the contract contains service-level agreements and indemnities
  2. BAccountability transfers to the provider only for activities classed as non-critical
  3. CThe bank's board and senior management remain ultimately accountable for outsourced activities and the risks they createCorrect
  4. DAccountability passes to the regulator if the provider is itself a supervised entity

Explanation

Supervisory guidance on outsourcing states that outsourcing does not relieve the board and senior management of responsibility. Contracts and SLAs can allocate liability and remedies but not regulatory accountability. The other options wrongly suggest accountability can be transferred.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions