FRM Part II · FRM Exam Part II · Risk Mitigation
Which contractual provision best supports a bank's ability to oversee an outsourced critical service on an ongoing basis?
A clause granting the bank and its regulators audit and access rights, together with defined service-level metrics, best supports ongoing oversight. It lets the bank verify controls and measure performance, whereas unnotified subcontracting, minimal reporting or vendor data ownership would weaken control.
- AA clause giving the bank and its regulators the right to audit and access the vendor's relevant records and facilities, plus defined service-level metricsCorrect
- BA clause allowing the vendor to change subcontractors without notice
- CA clause limiting the vendor's reporting to an annual summary
- DA clause stating that the vendor owns all data generated in the service
Explanation
Effective oversight requires audit and access rights for the bank and its supervisors and measurable service levels to monitor performance. The other clauses reduce transparency, weaken control over data or allow unmonitored subcontracting.
Did you get it right without looking?
One question tells you little. A timed set on Risk Mitigation shows your real accuracy, how long you take and where you lose marks.
More Risk Mitigation questions
- A bank considers insurance mitigation under an advanced measurement approach-style framework. A risk manager notes that the insurance policy…
- A risk manager compares two mitigation options for a fraud risk with expected annual loss of USD 2.0 million. Option A costs USD 0.6 million…
- A bank's ransomware scenario shows an annual probability of 5% and a loss of USD 40 million if it occurs. Management considers two options. …
- A bank estimates that, without a new email-filtering control, phishing-related losses would have an expected annual loss of USD 4.0 million.…
- A bank considers shifting part of its cyber risk to a captive insurance subsidiary that reinsures with external markets. Which statement bes…
- A bank has a cyber insurance policy with a USD 50 million limit. Its scenario analysis shows a severe but plausible cyber event could cause …