Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

After a vendor failure disrupts a bank's customer onboarding service, the board asks how operational resilience differs from traditional operational risk management. Which statement best captures the resilience approach?

Operational resilience assumes disruptions, including third-party failures, will occur. It therefore concentrates on keeping critical business services running within pre-defined impact tolerances, rather than trying to prevent every event or relying only on insurance or internally owned systems.

  1. AIt assumes disruptions will occur and focuses on delivering critical operations within defined impact tolerancesCorrect
  2. BIt aims to eliminate all operational loss events through stronger preventive controls
  3. CIt transfers all residual disruption risk to insurers so no tolerance needs to be set
  4. DIt limits scope to information technology systems owned by the bank

Explanation

Operational resilience accepts that disruptions will happen and focuses on continuing critical operations within impact tolerances, including those relying on third parties. Elimination of all events is unrealistic, insurance does not replace tolerances, and scope covers third-party services, not only owned IT.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions