Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

During due diligence on a cloud provider that will host a critical payments application, a risk manager finds the provider relies on a subcontractor for its data-center operations. What is the most appropriate lifecycle response?

The bank should assess the fourth-party risk and build contract terms giving visibility into subcontractors, flow-down of control requirements and notice of changes. The bank stays accountable for the service, so the subcontractor's risks cannot be ignored or postponed until later monitoring.

  1. AIgnore the subcontractor because the contract is only with the provider
  2. BAssess fourth-party risk and require contractual visibility, flow-down of controls and notification of subcontractor changesCorrect
  3. CTerminate the selection process because any subcontracting is prohibited
  4. DDefer the issue until the first annual monitoring review

Explanation

The bank remains accountable for outsourced activities, including those performed by subcontractors. Due diligence and contract terms should address fourth-party dependencies through transparency, control flow-down and notification rights. Ignoring or deferring leaves the concentration unmanaged; blanket prohibition is not required.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions