FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
Several banks in a jurisdiction rely on the same cloud provider for core payment processing. A supervisor wants a tool that directly addresses the resulting concentration risk at the system level. Which measure is most appropriate?
The most appropriate tool is mapping critical third-party dependencies and requiring exit plans, substitutability or direct oversight of the provider. This addresses the shared-provider concentration that creates correlated failure, whereas a generic countercyclical buffer relates to credit cycles and does not reduce operational concentration.
- ARequiring each bank to increase its general countercyclical capital buffer uniformly
- BMapping critical third-party dependencies and imposing exit plans, substitutability requirements or oversight of the providerCorrect
- CRestricting banks from publishing incident data
- DRaising each bank's deposit insurance premium
Explanation
Dependency mapping with exit and substitutability requirements, or direct oversight of critical providers, targets the shared-provider channel. A uniform countercyclical buffer is tied to credit cycles, not operational concentration, so it does not address the source of the risk.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- A regional bank migrates its core payment processing to a single cloud provider to cut costs. Which feature of this change most directly rai…
- A regional bank's security team detects a new ransomware variant targeting payment systems. It wants to alert peers quickly without exposing…
- An insurer writes cyber policies with a 1,000 policy portfolio, each with a 4 million limit. It estimates an independent annual claim probab…
- A supervisor is assessing why the cyber insurance market may be unable to absorb systemic digital shocks. Which feature of cyber risk most d…
- Which feature best describes threat-led penetration testing as used in digital resilience frameworks?
- A regional bank's risk committee is reviewing why supervisors increasingly treat cyber incidents as a potential threat to financial stabilit…