Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

Which element is most appropriate to include in a contract with a critical third-party provider to support ongoing oversight during the lifecycle's monitoring stage?

The contract should include defined service-level metrics, reporting duties, audit and access rights and incident notification timelines. These give the bank the information needed to monitor the vendor's performance and risks, whereas restricted audits, liability waivers or unrestricted subcontracting undermine oversight.

  1. AA clause limiting the bank's right to audit to once every five years
  2. BDefined service-level metrics, reporting obligations, audit and access rights, and incident notification timelinesCorrect
  3. CA clause removing the vendor's liability for data breaches
  4. DA provision allowing unrestricted subcontracting without notice

Explanation

Effective monitoring depends on contractual SLAs, reporting, audit and access rights and prompt incident notification, giving the bank evidence to oversee performance. The other clauses weaken oversight or shift risk inappropriately.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions