FRM Part II · FRM Exam Part II · Guidance on Managing Outsourcing Risk
An SLA for an outsourced KYC screening vendor reports that 98% of cases are processed within the target time, but the bank's risk team finds that the 2% of late cases are all high-risk customers. What is the best conclusion?
The SLA should be redesigned so metrics are segmented or risk-weighted, because a strong overall percentage hides that all late cases are high-risk customers. Service levels must reflect the risk the bank actually bears, not just aggregate averages.
- AThe SLA is adequate because the headline metric exceeds the target
- BThe SLA metrics should be redesigned to reflect risk-weighted or segmented outcomes, not just averagesCorrect
- CThe vendor should be terminated immediately
- DThe metric should be dropped because KYC cannot be measured
Explanation
Aggregate metrics can mask concentration of failures in the most important segment. Good SLAs align indicators with the bank's risk and criticality, so segmenting or weighting is appropriate. Immediate termination is disproportionate.
Did you get it right without looking?
One question tells you little. A timed set on Guidance on Managing Outsourcing Risk shows your real accuracy, how long you take and where you lose marks.
More Guidance on Managing Outsourcing Risk questions
- A mid-sized bank plans to outsource its customer onboarding checks to an external provider. Under the Federal Reserve's guidance on managing…
- A bank's senior management is approving a new outsourcing of cloud data hosting for its risk systems. Which sequence of management activitie…
- A bank's risk team reviews its critical outsourced services. Five critical services are provided by vendors: Vendor A supplies 3 services, V…
- Which description best captures outsourcing risk as a category of operational risk for a financial institution?
- Meridian Bank is evaluating two vendors for a critical payments-processing service. Which action best reflects sound due diligence BEFORE se…
- Which element is MOST appropriate to include in a written contract with a provider of a critical outsourced service?