A regional bank moves its core processing platform to a cloud vendor. The vendor outsources its data center to a third sub-processor in another country. Three quarters later the sub-processor suffers a multi-day outage and the bank cannot post deposits. Regulators ask who owns the customer harm. The contract names the cloud vendor, but the supervisory expectation is clear: the bank owns the risk because outsourcing the activity does not outsource the responsibility.
Banks outsource almost everything that is not customer-facing: core processing, payment rails, KYC checks, model validation, cybersecurity monitoring, even credit decisioning. The Fed's December 2013 "Guidance on Managing Outsourcing Risk" frames the basic rule. A financial institution can transfer execution to a third party but cannot transfer the regulatory obligation to manage that activity prudently. The board and senior management remain accountable.
The risks that arise through outsourcing fall into recognizable buckets. Operational risk shows up when a vendor fails to deliver service. Compliance risk shows up when a vendor's process violates a regulation that binds the bank.
Common mistakes
- Treating outsourcing as a transfer of regulatory responsibility. The activity is outsourced; the risk and the regulatory obligation stay with the firm. Trap: the choice that says "the bank can rely on the vendor's compliance program" is wrong; the bank must verify it independently.
- Ignoring concentration risk because each individual vendor passes due diligence. A vendor passes its own checks but the firm has fifteen critical services running on the same cloud. The aggregate concentration is the risk; per-vendor due diligence does not surface it.
- Confusing types of model error. Theoretical errors come from wrong math; implementation errors come from bad code or data; use errors come from applying the model outside its domain. Each has different detection mechanisms and different fixes. Trap: the question describes a use error and offers "fix the implementation" as a distractor.
Bottom line
- Outsourcing transfers the activity, not the risk. The Federal Reserve December 2013 guidance and FDIC SR 11-7 both place ultimate responsibility on the regulated firm's board and senior management.
- Five-stage third-party lifecycle: risk assessment, due diligence, contract negotiation, ongoing monitoring, and exit planning. Each phase carries documented expectations.
- Concentration risk dominates modern outsourcing as a few cloud and data providers serve the industry. Per-vendor due diligence does not surface it.
- Model risk has three sources: theoretical errors (wrong math), implementation errors (bugs and bad data), and use errors (model applied outside its design domain).
Exam shortcut
When a question describes a vendor failure, the answer almost always involves a missing contract provision (audit rights, subcontractor consent, exit clause) or inadequate ongoing monitoring. Memorize the contract checklist and you can identify the gap in the case description quickly. When a question describes a model failure, classify the error type first: theoretical, implementation, or use. The corrective action depends on the type.
The full lesson (about 3,195 words, 21 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
Browse all free FRM Part II lessons or jump into free FRM Part II practice questions.