FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
A risk officer reviews a bank's outsourcing register and finds that the contract with a critical cloud provider lacks an exit strategy and a regulator access clause. Which governance deficiency is most directly indicated?
It indicates weak contract governance and inadequate exit and continuity planning for a critical vendor. Supervisory expectations call for regulator and audit access clauses and documented exit strategies for material outsourcing, so missing both leaves the bank exposed to disruption and supervisory criticism.
- AWeak contract governance and inadequate business continuity and termination planning for a critical vendorCorrect
- BExcessive board involvement in vendor selection
- COverly strict internal audit independence
- DToo much diversification across vendors
Explanation
Supervisory guidance expects contracts for material outsourcing to include supervisor access and audit rights, and the bank to maintain exit and contingency plans. Their absence for a critical provider reflects weak contract governance and resilience planning. The other options do not describe the missing elements.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- Following a third-party outage, a bank reviews its exit planning for a critical outsourced service. Which element is most important for the …
- A bank's vendor contract for a customer-data hosting service contains a service level agreement (SLA). Which contract clause would most dire…
- After a vendor failure disrupts a bank's customer onboarding service, the board asks how operational resilience differs from traditional ope…
- After a vendor failure disrupted its trade settlement service, a bank's board wants to define its operational resilience tolerance for that …
- Which statement best describes the purpose of pre-contract due diligence on a prospective critical vendor?
- A bank's board is reviewing its third-party risk management framework. Which responsibility is most appropriately retained by the board rath…