FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management
Which element is most appropriate to include in a contract with a critical third-party provider to support ongoing oversight during the lifecycle's monitoring stage?
The contract should include defined service-level metrics, reporting duties, audit and access rights and incident notification timelines. These give the bank the information needed to monitor the vendor's performance and risks, whereas restricted audits, liability waivers or unrestricted subcontracting undermine oversight.
- AA clause limiting the bank's right to audit to once every five years
- BDefined service-level metrics, reporting obligations, audit and access rights, and incident notification timelinesCorrect
- CA clause removing the vendor's liability for data breaches
- DA provision allowing unrestricted subcontracting without notice
Explanation
Effective monitoring depends on contractual SLAs, reporting, audit and access rights and prompt incident notification, giving the bank evidence to oversee performance. The other clauses weaken oversight or shift risk inappropriately.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.
More Case Study: Third-party Risk Management questions
- A bank's outsourced call-centre vendor has an SLA requiring 99.5% availability over a 30-day month (720 hours). In the month, the vendor rec…
- A bank is drafting a contract with a vendor supporting a critical payments function. Which provision most directly supports the termination …
- A bank assesses 10 critical applications. Cloud Provider A hosts 4, Provider B hosts 3, Provider C hosts 2 and Provider D hosts 1. Using the…
- A bank uses a scorecard to rank vendors by residual risk. Inherent risk is scored 1-5 and control effectiveness reduces it by a factor: resi…
- A mid-sized asset manager is deciding whether to outsource its fund accounting function. Which of the following is the most typical strategi…
- A bank sets an impact tolerance of 8 hours maximum disruption for a critical payments service. A scenario test of a vendor failure shows: ve…