Skip to content

FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector

A regulator is designing a policy toolkit for digital resilience in the financial sector. It considers five tools: (1) mandatory incident reporting, (2) oversight of critical third-party providers, (3) threat-led penetration testing, (4) capital add-ons for operational risk, (5) cross-sector crisis simulation exercises. Which tool is most directly intended to address concentration risk from many institutions relying on the same cloud provider?

Direct oversight of critical third-party providers best addresses concentration risk from a shared cloud provider, because it targets the common dependency itself. Incident reporting, penetration testing and capital add-ons help with detection, defense or loss absorption but do not reduce the systemic reliance.

  1. AThreat-led penetration testing of each bank's own systems, because it exposes provider concentration
  2. BMandatory incident reporting, because it prevents provider outages
  3. COversight of critical third-party providers, because it targets the shared dependency directly rather than each institution separatelyCorrect
  4. DCapital add-ons, because capital eliminates the dependency on the provider

Explanation

Concentration in a shared provider is a systemic dependency that individual institutions cannot fully manage, so direct oversight of critical third parties is the tool aimed at it. Reporting aids detection, testing assesses defenses, and capital only absorbs losses without removing the dependency.

Did you get it right without looking?

One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.

More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions