Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

Before onboarding a new critical SaaS vendor, a bank wants to manage the risk that the vendor's own cloud host fails. Which action most directly addresses this fourth-party exposure?

The best action is to require contractual disclosure of material subcontractors, advance notice of changes and evidence of the vendor's resilience testing. This gives the bank visibility into the vendor's cloud host dependency and allows it to assess and monitor the fourth-party exposure.

  1. ARequire contractual disclosure of material subcontractors, notification of changes, and evidence of the vendor's resilience testingCorrect
  2. BRely solely on the vendor's marketing statements about uptime
  3. CLimit the review to the vendor's financial statements
  4. DAsk the vendor to waive all liability for outages

Explanation

Fourth-party risk is managed by visibility into the supply chain and by flow-down obligations and testing evidence. Marketing claims and financial review alone do not reveal dependencies. Waiving liability weakens the bank's position and does not reduce exposure.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions