Skip to content

FRM Part II · FRM Exam Part II · Guidance on Managing Outsourcing Risk

A risk manager reviews a bank's critical outsourcing of payment processing. The provider has been performing well for five years, and management proposes to cut oversight to an annual questionnaire. Which response best reflects expected senior management practice?

Management should reject the proposal because oversight must be ongoing and proportionate to the risk and criticality of the outsourced activity. Good past performance, contractual indemnities or the provider's own audit do not replace the bank's continuing monitoring of a critical payment service.

  1. AAccept, since five years of good performance removes the need for ongoing due diligence
  2. BAccept, provided the contract contains an indemnification clause covering all losses
  3. CReject; oversight should be continuous and proportionate to the criticality of the activity and the risk it posesCorrect
  4. DReject; oversight should be transferred to the provider's own internal audit function

Explanation

Guidance requires ongoing monitoring commensurate with the level of risk and the criticality of the service, so critical activities need robust, continuous oversight. Indemnification does not remove reputational or operational risk. Relying on the provider's own audit gives no independent assurance, so A, B and D fail.

Did you get it right without looking?

One question tells you little. A timed set on Guidance on Managing Outsourcing Risk shows your real accuracy, how long you take and where you lose marks.

More Guidance on Managing Outsourcing Risk questions