FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
After a vendor failure disrupts a bank's customer onboarding service, the board asks how operational resilience differs from traditional operational risk management. Which statement best captures the resilience approach?
Operational resilience assumes disruptions, including third-party failures, will occur. It therefore concentrates on keeping critical business services running within pre-defined impact tolerances, rather than trying to prevent every event or relying only on insurance or internally owned systems.
- AIt assumes disruptions will occur and focuses on delivering critical operations within defined impact tolerancesCorrect
- BIt aims to eliminate all operational loss events through stronger preventive controls
- CIt transfers all residual disruption risk to insurers so no tolerance needs to be set
- DIt limits scope to information technology systems owned by the bank
Explanation
Operational resilience accepts that disruptions will happen and focuses on continuing critical operations within impact tolerances, including those relying on third parties. Elimination of all events is unrealistic, insurance does not replace tolerances, and scope covers third-party services, not only owned IT.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A regional bank uses a single cloud provider to host its core banking, payments and fraud-detection systems. Which description best captures…
- A bank's vendor, which processes card transactions, subcontracts its data-center hosting to another firm that the bank has no contract with.…
- A bank discovers that business units have each signed vendor contracts independently, and no one can state how many critical third parties t…
- Before onboarding a new critical SaaS vendor, a bank wants to manage the risk that the vendor's own cloud host fails. Which action most dire…
- A bank assesses an outsourced critical service. The primary vendor has a 2% annual probability of a disruption exceeding the bank's impact t…
- Following a vendor failure, a bank's review finds its contract lacked exit provisions, audit rights and incident notification timelines. At …