Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

Which role is the internal audit function expected to perform with respect to a bank's third-party risk management framework?

Internal audit should give independent assurance on whether the third-party risk framework is well designed and operating effectively. It does not perform due diligence, approve contracts or manage vendor relationships, because those are first- and second-line tasks and would undermine its independence.

  1. AOwn and execute vendor due diligence for all contracts
  2. BProvide independent assurance on the framework's design and operating effectivenessCorrect
  3. CApprove each new outsourcing contract before signing
  4. DAct as the provider's relationship manager

Explanation

Internal audit is the third line and gives independent assurance. Due diligence, contract approval and relationship management are first- or second-line activities, and performing them would compromise audit independence.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions