Skip to content

FRM Part II · FRM Exam Part II · Guidance on Managing Outsourcing Risk

A risk manager designs management reporting on a bank's critical outsourcing arrangements for the board. Which approach is most consistent with good practice?

Good practice is regular board and senior management reporting on critical providers covering key risk indicators, incidents, service level performance and concentration, with clear escalation of exceptions. Vendor lists, breach-only reports or provider-controlled reporting do not give timely, independent insight.

  1. AProvide only an annual list of all vendors and contract values
  2. BReport only when a provider breaches its contract
  3. CProvide periodic summaries of key risk indicators, incidents, SLA performance and concentration for critical providers, with escalation of exceptionsCorrect
  4. DDelegate all reporting to the provider's own relationship managers

Explanation

Effective oversight needs regular, risk-focused information on critical providers, including KRIs, incidents, performance and concentration, with escalation triggers. A static list, breach-only reporting, or provider-controlled reporting lacks timeliness or independence.

Did you get it right without looking?

One question tells you little. A timed set on Guidance on Managing Outsourcing Risk shows your real accuracy, how long you take and where you lose marks.

More Guidance on Managing Outsourcing Risk questions