FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
A supervisor is designing a framework to limit systemic risk from the concentration of many banks on a single cloud provider. Which policy tool is most directly aimed at this specific concern?
Direct oversight or designation of critical third-party providers, plus exit and substitutability requirements, targets cloud concentration. The risk is a common operational dependency across institutions, which capital, liquidity or leverage buffers do not address because they absorb financial losses rather than prevent shared service failure.
- ARaising the minimum CET1 ratio for all banks equally
- BDirect oversight or designation of critical third-party providers, combined with exit and substitutability requirements for financial institutionsCorrect
- CRequiring banks to hold more high-quality liquid assets against deposit outflows
- DImposing a leverage ratio buffer on global systemically important banks
Explanation
Cloud concentration is a third-party dependency risk, which is addressed by oversight of critical providers and requirements for exit strategies and substitutability. Capital and liquidity buffers address financial losses and funding, not a common operational failure point.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- Which policy tool is most directly aimed at reducing systemic cyber risk arising from firms' reliance on critical third-party providers?
- A risk analyst compares two ways of modelling extreme cyber losses for the financial sector. Historical data are scarce and incidents are hi…
- Which policy approach best addresses the systemic nature of cyber risk, as opposed to purely firm-level controls?
- A financial stability authority is designing a macroprudential framework for cyber risk. Which feature most distinguishes a macroprudential …
- A risk officer argues that digital resilience policy should move beyond capital buffers. Which reasoning best supports this view?
- A regulator is designing a framework for operational resilience across the financial sector. Which design choice best reflects a sound macro…