FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
Before onboarding a new critical SaaS vendor, a bank wants to manage the risk that the vendor's own cloud host fails. Which action most directly addresses this fourth-party exposure?
The best action is to require contractual disclosure of material subcontractors, advance notice of changes and evidence of the vendor's resilience testing. This gives the bank visibility into the vendor's cloud host dependency and allows it to assess and monitor the fourth-party exposure.
- ARequire contractual disclosure of material subcontractors, notification of changes, and evidence of the vendor's resilience testingCorrect
- BRely solely on the vendor's marketing statements about uptime
- CLimit the review to the vendor's financial statements
- DAsk the vendor to waive all liability for outages
Explanation
Fourth-party risk is managed by visibility into the supply chain and by flow-down obligations and testing evidence. Marketing claims and financial review alone do not reveal dependencies. Waiving liability weakens the bank's position and does not reduce exposure.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A regional bank relies on a single cloud provider to host its payment processing platform. The provider suffers a multi-day outage, and the …
- A mid-sized asset manager is considering outsourcing its fund-accounting function. Which motivation is most consistent with a sound strategi…
- A bank outsources its cloud hosting to Provider A, which in turn subcontracts data storage to Provider B. A fire at B's facility interrupts …
- A bank's vendor, which processes card transactions, subcontracts its data-center hosting to another firm that the bank has no contract with.…
- A bank discovers that business units have each signed vendor contracts independently, and no one can state how many critical third parties t…
- During ongoing monitoring, a bank notes that a critical cloud provider has begun subcontracting its data-hosting to a fourth party in anothe…