Bank Promotion Exam Guide

Banking Awareness | Banking Knowledge | for all Bank Exams

Module: | MODULE B: RISK MANAGEMENT

Q415: Scenario: A commercial bank outsources its core banking server hosting to a third-party cloud service provider. Due to a critical failure at the vendor's data center, the bank faces a 12-hour complete system outage, resulting in major financial and customer service losses. Based on RBI guidelines regarding Information Technology outsourcing, consider the following statements:

1. Since the core banking server was entirely outsourced, the primary operational risk and regulatory accountability are legally transferred to the third-party vendor.
2. The RBI mandates that despite the outsourcing arrangement, the bank retains ultimate accountability for the operational failure and related losses.
3. The bank must record this third-party failure event in its own internal Loss Data Collection (LDC) database under "Business Disruption and System Failures".

Which of the statements given above is/are correct?
A
Only 1 and 2
B
Only 2 and 3
C
Only 1 and 3
D
1, 2, and 3 [AnswerTTS: सही जवाब है ऑप्शन बी... यानी केवल स्टेटमेंट दो और तीन सही हैं. आइए इस *💻Scenario: IT Outsourcing* आईटी आउटसोर्सिंग वाले गंभीर मामले को *🏛️Regulator: RBI Rules* आरबीआई नियमों के तहत जांचते हैं. जब कोई बैंक अपना *⚙️System: Core Banking* कोर बैंकिंग सर्वर किसी *🌐Vendor: Third Party* थर्ड पार्टी को आउटसोर्स करता है, तो वह सिर्फ काम ट्रांसफर करता है, *🚫Rule: No Risk Transfer* रिस्क ट्रांसफर नहीं कर सकता. बैंक यह कहकर नहीं बच सकता कि गलती वेंडर की थी. इसलिए *❌Result: Statement 1 Incorrect* स्टेटमेंट एक पूरी तरह गलत है. रिज़र्व बैंक की स्पष्ट *📜Guideline: Master Direction* गाइडलाइन है कि आउटसोर्सिंग के बावजूद, ऑपरेशन्ल रिस्क और *👑Responsibility: Ultimate Accountability* अंतिम जवाबदेही हमेशा बैंक की ही रहती है. बैंक को ही ग्राहकों और *🏛️Authority: Regulator* रेगुलेटर को जवाब देना होगा. इसलिए *✅Result: Statement 2 Correct* स्टेटमेंट दो बिल्कुल सही है. अब चूंकि ज़िम्मेदारी बैंक की है, तो जो भी *💸Impact: Financial Loss* आर्थिक नुकसान हुआ है, उसे बैंक को अपने *💾Database: Internal LDC* इंटरनल एलडीसी डेटाबेस में दर्ज करना होगा. इसे बेसल के *🔌Event: Business Disruption* बिज़नेस डिसरप्शन एंड सिस्टम फेलियर इवेंट टाइप के तहत *📝Action: Record* बुक किया जाएगा, भले ही सर्वर वेंडर का था. इसलिए *✅Result: Statement 3 Correct* स्टेटमेंट तीन भी सही है. डिजिटल बैंकिंग के दौर में *🛡️Focus: Vendor Risk* वेंडर रिस्क मैनेजमेंट बैंकों के लिए सबसे बड़ी *⚠️Priority: High Priority* चुनौती बन गया है. ]
✅ Correct Answer: B
The correct answer is B. Statement 1 is incorrect: A fundamental principle of banking regulation and RBI guidelines on IT outsourcing is that management can outsource operational execution, but they can NEVER outsource regulatory compliance, risk ownership, or ultimate accountability.
The bank remains fully responsible for the third-party's failures.
Statement 2 is correct: As per RBI Master Directions, the regulated entity (the bank) retains ultimate control and accountability for outsourced activities.
The bank must ensure the vendor adheres to the same security and operational standards expected of the bank itself.
Statement 3 is correct: Because the risk and the ultimate financial loss impact the bank directly, this downtime and associated losses must be formally recorded in the bank's own Loss Data Collection (LDC) system.
The correct Basel event type for a vendor data center crash is "Business Disruption and System Failures".

Therefore:
Option A is incorrect because Statement 1 is false.
Option B is correct as both Statement 2 and 3 are true.
Option C is incorrect because Statement 1 is false.
Option D is incorrect because Statement 1 is false.