Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

During ongoing monitoring, a bank notes that a critical cloud provider has begun subcontracting its data-hosting to a fourth party in another jurisdiction, without informing the bank. Which response best reflects sound lifecycle practice?

The bank should reassess the arrangement, check the contract's subcontracting and notification clauses, and obtain assurance about the fourth party's controls and data location. Accountability stays with the bank even when services are subcontracted, so ignoring or abruptly ending the relationship would both be inappropriate.

  1. AAccept the change because the bank's contract is only with the provider, so fourth-party risk is the provider's responsibility alone
  2. BTerminate the contract immediately without assessing the impact
  3. CReassess the arrangement, review contractual subcontracting and notification clauses, and obtain assurance on the fourth party's controls and data locationCorrect
  4. DReduce monitoring frequency because the provider's risk is now diluted across more parties

Explanation

The bank remains accountable for outsourced activities, including those subcontracted. It should reassess risk, enforce notification and subcontracting provisions, and seek assurance over the fourth party. Immediate termination is disproportionate, and accepting or reducing monitoring ignores concentration and data risk.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions