Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

A risk officer reviews a bank's outsourcing register and finds that the contract with a critical cloud provider lacks an exit strategy and a regulator access clause. Which governance deficiency is most directly indicated?

It indicates weak contract governance and inadequate exit and continuity planning for a critical vendor. Supervisory expectations call for regulator and audit access clauses and documented exit strategies for material outsourcing, so missing both leaves the bank exposed to disruption and supervisory criticism.

  1. AWeak contract governance and inadequate business continuity and termination planning for a critical vendorCorrect
  2. BExcessive board involvement in vendor selection
  3. COverly strict internal audit independence
  4. DToo much diversification across vendors

Explanation

Supervisory guidance expects contracts for material outsourcing to include supervisor access and audit rights, and the bank to maintain exit and contingency plans. Their absence for a critical provider reflects weak contract governance and resilience planning. The other options do not describe the missing elements.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions