Skip to content

FRM Part II · FRM Exam Part II · Guidance on Managing Outsourcing Risk

Which item is most appropriately examined during due diligence of a prospective service provider's information security and business continuity capabilities?

Due diligence should examine the provider's security controls, incident response and disaster recovery plans, and test results, checking alignment with the bank's own standards. Brand, price or executive profiles say nothing about the provider's ability to protect data and maintain service.

  1. AThe provider's logo and brand recognition
  2. BIts security controls, incident response and disaster recovery plans, and results of testing, including whether they align with the bank's own requirementsCorrect
  3. COnly the price of the service
  4. DThe personal social media activity of its executives

Explanation

Due diligence on security and continuity looks at controls, incident response, recovery plans and test results and compares them with the bank's standards. Brand, price and executive social media do not demonstrate resilience.

Did you get it right without looking?

One question tells you little. A timed set on Guidance on Managing Outsourcing Risk shows your real accuracy, how long you take and where you lose marks.

More Guidance on Managing Outsourcing Risk questions