FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
During ongoing monitoring, a bank notes that a critical cloud provider has begun subcontracting its data-hosting to a fourth party in another jurisdiction, without informing the bank. Which response best reflects sound lifecycle practice?
The bank should reassess the arrangement, check the contract's subcontracting and notification clauses, and obtain assurance about the fourth party's controls and data location. Accountability stays with the bank even when services are subcontracted, so ignoring or abruptly ending the relationship would both be inappropriate.
- AAccept the change because the bank's contract is only with the provider, so fourth-party risk is the provider's responsibility alone
- BTerminate the contract immediately without assessing the impact
- CReassess the arrangement, review contractual subcontracting and notification clauses, and obtain assurance on the fourth party's controls and data locationCorrect
- DReduce monitoring frequency because the provider's risk is now diluted across more parties
Explanation
The bank remains accountable for outsourced activities, including those subcontracted. It should reassess risk, enforce notification and subcontracting provisions, and seek assurance over the fourth party. Immediate termination is disproportionate, and accepting or reducing monitoring ignores concentration and data risk.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A bank outsources its customer onboarding checks to a vendor, which in turn uses a subcontractor in another jurisdiction for document verifi…
- A bank's cloud vendor contract states that the vendor is responsible for the security of the cloud infrastructure, while the bank configures…
- A bank has five critical services. Service dependency mapping shows: Provider A supports 3 services, Provider B supports 2 services, and Pro…
- A bank is onboarding a cloud analytics vendor that will process confidential customer data and whose failure would halt daily risk reporting…
- A bank maps the dependencies of its payments service and finds that three apparently independent vendors all run on the same underlying clou…
- A bank's vendor risk team discovers that three of its critical service providers, each assessed as independent, all rely on the same subcont…