| Guidelines This chapter sets out principles for the management of third-party risks. The contents of this chapter are based on:
|
| Related standards |
| Related guidelines
|
| Other related publications |
Banks have long relied on arrangements with third-party service providers (TPSPs) for reasons such as to access specialised expertise, reduce costs, improve scalability, efficiency and operational resilience, and to focus on core activities. Ongoing digitalisation has led to a rapid adoption of innovative approaches, which has increased banks’ dependency on TPSPs for services that banks had not previously undertaken.
Appropriate risk management of banks’ TPSP arrangements, supply chain (ie nth parties), concentration risk and other risks arising therefrom can enhance banks’ ability to withstand, adapt to and recover from operational disruption and thereby mitigate the impact of potentially severe disruptive events.
The following terms are used throughout this chapter and have the meaning given below:
| 1 | For a definition of “systemic” see International Monetary Fund, Bank for International Settlements and Financial Stability Board, Guidance to assess the systemic importance of financial institutions, markets and instruments: initial considerations, October 2009. |
| 2 | Supervisors in some jurisdictions use terms such as “material services” and “important services” in a synonymous way. However, such concepts are often used to qualify the nature of services provided by a bank to its customers. |
| 3 | See also ORR20. |
| 4 | Branches are not considered intragroup providers, as they are not separate legal entities from their head offices. However, the provision of services from a head office of a bank to its overseas branches, or between branches, is not riskless. Therefore, in practice a proportionate risk-based approach to risk management and oversight of head office/branch relationships may be appropriate. Additionally, in contrast to the FSB’s toolkit this definition does not use the term “predominantly” to align with ORR10. |
| 5 | The Principles exclude nth parties from “TPSP arrangement” and instead provide specific expectations for managing nth parties when necessary, given the lack of a direct relationship between banks and nth parties. This highlights the different risk management approaches for TPSPs compared with nth parties. Furthermore, it is worth noting that the Principles in this chapter could also provide value for other types of relationships that banks may have with third parties, including joint support for banking products. |
| 6 | The term “arrangement” was used to align with ORR10. It is synonymous with the term “relationship” as used in the FSB’s report on Enhancing third-party risk management and oversight – a toolkit for financial institutions and financial authorities. |
| 7 | The Principles include intragroup entities in the definition of TPSPs when they function as third-party service providers. Although ORR20 differentiates between “third party” and “intragroup”, the risk management requirements for third-party dependencies outlined in both chapters apply equally to both categories. |
| 8 | The exclusion of the FMIs is not intended to imply that banks should not take appropriate steps to manage risk in these arrangements. Rather, it is intended to avoid duplication and unintentional conflicts between the Principles and standards and guidance specific to FMIs. |
The Principles seek to achieve a balance between improving practices related to the management of third parties and providing a common baseline for banks and supervisors, while maintaining sufficient flexibility given the evolution of practices in this area. The Principles offer guidance on holistic third-party risk management for banks, allowing them the flexibility to tailor their TPRM practices based on the risks and the criticality of their TPSP arrangements. Further, the Principles outline additional expectations with regard to critical TPSP arrangements. The Principles are technology-agnostic to maintain relevance as technology develops. They aim to promote international engagement, as well as greater collaboration and consistency, with a view to reducing regulatory fragmentation.
The Principles seek to accommodate a diverse range of bank risk management practices and approaches. They are intended to be applied on a proportionate basis depending on the size, complexity, business model and risk profile of the bank, as well as the risks and criticality of the TPSP arrangements.
These Principles address risk management on a consolidated and on an individual bank basis. Whether activities are performed internally or by a TPSP, banks are required to operate in a safe and sound manner and in compliance with applicable laws and regulations. While the use of TPSPs can reduce banks’ direct control over their activities and assets (including data) and may introduce new risks or increase existing risks, the use of TPSPs should neither diminish banks’ responsibility to fulfil their obligations to stakeholders (eg customers, supervisors and other legal authorities) nor impede effective regulatory oversight. As with all business processes, documentation evidencing TPRM processes (eg risks assessment and due diligence results, selection of TPSPs, and monitoring and termination of TPSP arrangements) and decisions (eg third-party strategy and board minutes reflecting a decision to enter into a critical TPSP arrangement) should be maintained in banks’ records.
The Committee has designed these Principles to provide guidance to banks on TPRM. Financial institutions other than banks may find these Principles beneficial in addition to the international guidance applicable to their sector. Many jurisdictions have developed their own TPRM frameworks and standards, which are unique to jurisdiction(s) and are designed according to legal and regulatory obligations.
These Principles also aim to complement the work of other international standard-setting bodies addressing TPRM in the financial sector, including but not limited to the following:
Effective TPRM generally follows the stages of the life cycle for TPSP arrangements. Controls should be designed proportionally to the risks and criticality of each TPSP arrangement. A framework for TPRM benefits from identifying the risks and criticality of bank operations supported by a TPSP arrangement at inception and periodically (eg renewals) throughout its life cycle. The stages of the life cycle typically include risk assessment, due diligence,9 contracting, onboarding and ongoing monitoring, and termination. The bank’s governance, risk management and strategy are integral to each stage of the life cycle. The stages of the life cycle are shown in Graph 1, with detailed descriptions given in the respective subsections.
| Graph 1: Third-party arrangement life cycle |
| |
| 9 | Risk assessment focuses on the service arrangement, while due diligence concentrates on the specific prospective TPSP. |
The stages of the life cycle do not necessarily reflect a linear progression. Rather, the output of each stage should serve as factors to consider in the subsequent and prior stages. For example, a bank may leverage information gained in response to an incident during the onboarding and ongoing monitoring stage for updating its initial risk assessment and due diligence processes of that TPSP.
The following key concepts are embedded in all stages of the life cycle and apply to all Principles:
Principle 1: The board of directors has ultimate responsibility for the oversight of the bank’s third-party risks and should approve a clear strategy and define the bank’s risk appetite and associated tolerance for disruption.
Principle 2: The board of directors should ensure that senior management implements policies and processes of the third-party risk management framework (TPRMF) in line with the bank’s third-party strategy, including reporting of TPSP performance and risks related to TPSP arrangements, and mitigating actions to the board of directors.
Banks should implement a TPRMF,10 supported by a strong governance structure led by the board of directors and effective risk management aligned with the banks’ business strategy (eg business needs, and overall strategic goals and objectives), risk management strategy and third-party strategy (refer to section on Strategy below). Consistent with the Principles outlined in ORR10 and ORR20, banks’ TPRMF should align with their: (i) governance; (ii) risk management practices; and (iii) strategy.
Senior management should ensure communication of the bank’s third-party strategy and policy to all relevant stakeholders, including bank personnel and intragroup entities, and should establish policies and procedures that include clearly defined roles and responsibilities to manage TPSP arrangements throughout the third-party arrangement life cycle.
The bank’s third-party arrangement life cycle and services under TPSP arrangements should be integrated into the three lines of defence.12 Roles and responsibilities of all staff should be appropriately defined. Based on risk and complexity, banks may establish a central function to monitor all TPSP arrangements.
There are certain arrangements with TPSPs which entail “shared responsibility”13 between the bank and the TPSP. The concept of shared responsibility does not abrogate the board of directors’ ultimate responsibility for oversight of the banks’ third-party risks.
| 13 | See Basel Committee on Banking Supervision, Digitalisation of finance, May 2024. |
A bank’s TPRMF should consider the bank’s size, complexity, business model, risk profile and cross-border presence as well as the risks and criticality of the TPSP arrangements. The TPRMF should clearly outline criteria, processes and frequency for: (i) risk identification and assessment; (ii) monitoring and reporting; and (iii) application of controls.
Banks should maintain complete and up-to-date registers of all TPSP arrangements and key nth parties. Banks should include key elements of each arrangement in the registers (eg criticality of the arrangement, substitutability of the TPSP’s services, contingent providers, whether proprietary or confidential information is shared, location(s) of service and data, and legal entity identifier (LEI), where available). Registers should be updated periodically or when there are relevant changes (eg entering into another arrangement with the TPSP, changes in contractual terms, changes in criticality, changes to the service location, availability of a contingent provider, and mergers and acquisitions). Banks should use the information in the registers to map dependencies and interconnections related to arrangements, particularly those associated with higher levels of risks and those supporting critical services. Banks should be prepared to share the registers with supervisors when requested (as per jurisdictional requirements).
Banks should assess the bank-level concentration risk initially at the time of due diligence, and periodically throughout the life cycle of the TPSP based on changes in the TPSP portfolio. Up-to-date third-party registers and mapping of dependencies and interconnections facilitate the identification of bank-level concentration risk of TPSPs. Where exposed to bank-level concentration risk including concentrations in their supply chains, banks should enhance monitoring and other measures (eg testing at more frequent intervals) to mitigate the risk of critical TPSP arrangements. Banks should also explore multiple options (eg the provision of critical services from multiple geographic regions by a single provider, ensuring that TPSPs adequately manage the resilience of their supply chains, combining the use of banks’ on-premises infrastructure with TPSPs’ services, backup or alternative TPSPs, and retaining capability to bring the service back in-house) to manage bank-level concentration risk within their risk appetite and tolerance for disruption.15
The board of directors should approve a TPRM strategy (which could also be part of the bank’s overall risk management strategy). It should be consistent with other relevant strategies and the bank’s risk appetite. It should cover the following:
Banks’ risk appetite, risk tolerance16 and tolerances for disruption should reflect the risks from TPSP arrangements, be forward-looking and, where applicable, subject to scenario and stress testing. This includes consideration of the risks and benefits posed by new or advanced technologies when developing their third-party strategy, and as part of the implementation of their TPRMF.
Banks should maintain an adequate level of staffing, in-house knowledge, experience, competency, and training and awareness programmes to identify, assess, manage and monitor the risks posed by TPSP arrangements. Banks may engage external support to supplement the qualifications and technical expertise of in-house staff.
Principle 3: Banks should perform a comprehensive risk assessment under the TPRMF to evaluate and manage identified and potential risks both before entering into and throughout the life cycle of a TPSP arrangement.
The risk assessment stage of the life cycle is where banks identify and assess:
As part of assessing the types and levels of risks, banks should consider risks related to TPSP arrangements, including bank-level concentration risk, the risk stemming from a long or complex supply chain, as well as new or advanced technologies, and other financial and non-financial risk. Complimentary to this is the assessment of criticality. Banks should consider their tolerance for disruption of the service provided by the TPSP; the nature of any data or information shared with the TPSP; or the substitutability of the service. Banks should also assess the potential impacts of entering into any TPSP arrangement on their operations (eg activities, functions, systems and data). Further, banks should document the methodology and results of the analysis performed.
Based on the risk assessment results, banks should:
In their risk assessments, banks should consider how an arrangement would align with their TPRMF and TPRM policies, and consider the expected benefits and costs of the proposed TPSP arrangement. The outcome of the risk assessment should enable a bank to make an informed decision on whether to engage a TPSP. This risk assessment would be complemented by a TPSP-specific risk assessment (eg TPSP’s size and complexity) (refer to section on Due diligence).
The risk assessment is an iterative process throughout the life cycle of a TPSP arrangement. Risks may change throughout the life cycle of the TPSP arrangement. Therefore, banks should perform risk assessments on a regular basis and whenever there are major changes impacting the arrangement (refer to Onboarding and ongoing monitoring below).
Principle 4: Banks should conduct appropriate due diligence on a prospective TPSP prior to entering into an arrangement.
The due diligence stage of the life cycle is where banks gather and analyse the information needed to determine how well an arrangement with a specific TPSP would support their third-party strategy. Banks should also perform due diligence to evaluate whether they would be able to appropriately identify, monitor and manage risks associated with the specific arrangement with a prospective TPSP.
Banks should have an appropriate and proportionate process for selecting and assessing the prospective TPSP before entering into a TPSP arrangement. The risk associated with a specific TPSP could affect the overall risk assessment of a bank’s existing TPSP arrangements profile.
Banks’ due diligence, including inputs from monitoring any relevant prior arrangements, should support the analysis of:
Aspects that should be considered under each of these dimensions are outlined below.
As part of the assessment of a TPSP’s capacity and ability to deliver the services under the arrangement, banks should consider the TPSP’s:
As part of the assessment of known and potential risks associated with TPSPs, banks should consider:
As part of the assessment of relative benefits and costs associated with the TPSP arrangement, banks should consider:
Principle 5: TPSP arrangements should be governed by legally binding written contracts that clearly describe rights and obligations, responsibilities and expectations of all parties in the arrangement.
The contracting stage of the life cycle is when negotiations between a bank and a TPSP occur, and where terms and conditions of the delivery of services are agreed. Contractual provisions should facilitate effective risk management and oversight of the TPSPs and relevant services by the banks, and specify the expectations and obligations of both the banks and TPSPs. Banks should negotiate a contract that meets their own business goals and risk management needs.
TPSP arrangements should be governed by clearly written, legally binding contracts.20 The nature and details of these contracts should be appropriate to the banks and to the risks and criticality of the services provided by the TPSPs and reflect legal and regulatory obligations in the jurisdictions where the banks and TPSPs operate.
| 20 | In cases where a legally binding contract may not be possible, for example where the TPSP is a branch of the bank and thus not a legally distinct entity, it may be useful to have an SLA to formally document the services required by the branch, the roles and responsibilities of the involved parties including service standards, and the consequences of not meeting these standards. This may be particularly useful in cases where the branch needs to meet local regulatory requirements, for instance with respect to operational resilience, for the services it provides locally. |
Banks’ contracts governing TPSP arrangements should consider:
Banks’ contracts governing critical TPSP arrangements should include the provisions covered in ORR30.42 and those listed below:
In exceptional cases where a legally binding contract does not exist, banks remain responsible for appropriate risk management and oversight of their TPSP arrangements as outlined in this document.
Principle 6: Banks should dedicate sufficient resources to support a smooth onboarding of a new TPSP, including for the resolution of any issues identified during due diligence or interpretation of contractual provisions.
When a TPSP is onboarded, banks should ensure that the TPSP has adequate understanding of the bank’s policies, people, processes, technology, facilities and the interconnections that are needed to provide the contracted service, in compliance with laws and regulations. Each time banks onboard a new TPSP they should update their registers and map interdependencies (refer to ORR30.21).
Principle 7: Banks should, on an ongoing basis, assess and monitor the performance and changes in the risks and criticality of TPSP arrangements and report accordingly to board and senior management. Banks should respond to issues as appropriate.
The ongoing monitoring stage is where banks should:
Ongoing monitoring should be aligned with banks’ governance, risk management and strategy, the risks considered when the TPSP was selected, any new risks that have emerged since onboarding and contractual obligations of the TPSPs. It should include key nth parties.
All TPSP arrangements should be reviewed and assessed on a regular basis and whenever there are major changes in a bank’s internal environment (eg organisation or conflicts of interest), the TPSP (eg organisation, location of services, and introduction of new or advanced technologies) or the external environment (eg political, economic, social, legal and financial landscape, and any potential impediments to the delivery of activities). TPSP arrangements that pose a higher level of risks and/or critical TPSP arrangements should be assessed more frequently.
Monitoring should include performance-related metrics, such as ongoing key performance indicators and scorecards in line with banks’ policies and procedures used to check compliance with SLAs, contractual provisions, regulatory expectations and legal requirements. Banks should keep updated registers of all TPSP arrangements and key nth parties, reflecting any changes in risks and criticality (refer to ORR30.21). Banks should also maintain an up-to-date mapping of their interdependencies or interconnections for critical TPSP arrangements including for key nth parties.21 Banks should leverage this information to identify and monitor bank-level concentration risk at a frequency commensurate with the changes to the operating environment.
In arrangements involving shared responsibility, banks should monitor TPSP performance and operational implementation to ensure that obligations and responsibilities are clearly understood and fulfilled by the TPSP. Banks should also monitor their internal control environment and processes to meet their obligations and responsibilities.
Banks should review BCPs and DRPs of critical TPSPs and ensure that periodic testing is performed by TPSPs (refer to section on Business continuity management).
Banks may utilise the results of independent audits and other forms of assurance on the services contracted to TPSPs. However, for critical services, they should use multiple forms of assurance and not rely solely on one. Standardised assurances (eg ISO certificates) need to be critically assessed and fully understood to allow banks to identify their relevance compared with the banks’ internal standards and requirements.
The outcome of the risk assessments (eg portfolio level and critical services level) should be reported to senior management and boards of directors periodically and as needed according to banks’ policies and procedures. Reporting should encompass:
Effective risk management includes monitoring, reporting and responding to incidents, including those originating from TPSPs contracted to provide services to banks. Where applicable, banks must comply with all reporting obligations to authorities regarding incidents and contract provisions should provide banks with the ability to monitor incidents related to TPSPs (refer to section on Contracting). For critical services, banks should incorporate requirements related to incident reporting in the contracts, including minimum information to be reported. Contracts may require TPSPs to have clearly defined processes for identifying, investigating and remediating incidents related to contracted services and notifying banks in a timely manner of incidents that impact the TPSP’s ability to meet contractual obligations. Banks’ ongoing monitoring processes should include monitoring of incident response at TPSPs. Banks should integrate the remediation and reporting of incidents related to TPSPs into their broader risk management processes (eg threat and intelligence gathering and BCP). Banks should also analyse updates on the remediation of reported incidents and use this information to update their risk assessments of TPSPs.
Ongoing monitoring could result in differing responses by banks, including processes for incident management, renewal of contract or termination of a contract.
If the outcome of ongoing monitoring is not satisfactory or in case of a disruption of services provided by TPSPs, banks’ monitoring should provide timely:
When banks decide to renew a TPSP arrangement, they should leverage the information obtained from the onboarding and ongoing monitoring stage in performing due diligence prior to renewing the arrangement.
When monitoring determines that a given TPSP is no longer a viable option and banks decide not to renew a TPSP arrangement, they should ensure continuity of their operations and manage termination in the least disruptive manner (refer to section on Termination).
Principle 8: Banks should maintain robust business continuity management to ensure their ability to operate in case of a TPSP service disruption.
Banks should manage their dependencies on TPSP arrangements within their BCM processes. Banks’ BCM processes should consider:
Banks’ BCM processes governing critical TPSP arrangements should include the provisions covered in ORR30.62 and those listed below:
For critical TPSP arrangement, banks should also consider joint design and testing of BCPs, or utilise an independent party or parties to do the same (refer to “Audits and assurance” in ORR30.11).
Principle 9: Banks should maintain exit plans for planned termination and exit strategies for unplanned termination of TPSP arrangements.
The termination stage is where banks manage planned or unplanned (unexpected) terminations of arrangements for reasons such as expiration or breach of the contract, the TPSP’s failure to comply with applicable laws or regulations, or a desire to seek an alternate TPSP, bring the activity in-house or discontinue the activity. When this occurs, it is important for banks to terminate the arrangement in a safe and sound manner.
Banks should maintain appropriate and proportionate exit plans for planned terminations. Exit plans need to be regularly updated and tested for availability of budget, human resources, technical infrastructure, transfer of knowledge, access to data and other factors. The level of detail in the plans should be commensurate with the criticality and substitutability of the services provided.
Banks’ plans for the termination of TPSP arrangements should consider:
Banks’ exit plans for the termination of critical TPSP arrangements should include the provisions covered in ORR30.69 and those listed below:
Banks should maintain appropriate and proportionate exit strategies for unplanned terminations for all TPSP arrangements taking into consideration the criticality and substitutability of the services provided. Although unplanned terminations may occur less frequently than planned terminations, they potentially pose more risks and banks should prepare for such events. Such exit strategies for unplanned termination should be based on plausible scenarios and reasonable assumptions.
Banks’ exit strategies for the unplanned termination of critical TPSP arrangements should include:
Principle 10: Supervisors should evaluate third-party risk management as an integral part of ongoing assessment of banks.
Supervisors recognise that banks’ dependencies on TPSPs, if not managed appropriately, may impede their ability to fulfil their regulatory requirements. Supervisors should, therefore, assess banks’ TPRMF and consider how they align to their ORMF and support their operational resilience. Supervisory evaluations should cover the entire third-party arrangement life cycle. Emphasis should be placed on how banks integrate TPSP arrangements within their overall risk management processes (eg incident management, cyber security processes and BCM).
Principle 11: Supervisors should analyse the available information to identify potential systemic risks, including those posed by the concentration of one or multiple TPSPs providing services to the banking sector.
Concentration of services provided by TPSPs, combined with other factors (eg lack of substitutability of TPSPs or TPSPs’ access to banks’ sensitive data), are relevant to the identification of systemic risks. To assess and monitor such risks across the banking sector, supervisors should be able to obtain information from banks on their arrangements with TPSPs.24 The types of information supervisors could leverage include registers of TPSP arrangements; maps of interconnections and interdependencies;25 recovery and resolution plans; and reports on incidents involving TPSPs. To analyse systemic concentration risk, supervisors may assess banks’ aggregate TPRM capabilities using common supervisory tools (eg scenario analysis and data analytics). Based on the assessment, supervisors could further evaluate the potential systemic risk mitigation measures within their powers.
Principle 12: Supervisors should promote coordination and dialogue across sectors and borders to monitor systemic risks posed by critical TPSPs that provide services to banks.
Bank supervisors should promote coordination and dialogue among themselves, supervisors of other sectors (eg FMIs, telecommunications, energy and data protection authorities) and relevant stakeholders to monitor systemic risk. Such collaboration may include a variety of efforts to support the resilience of critical infrastructure (eg industry- and/or supervisory-led business continuity exercises).
Additionally, collaboration may comprise:
This module describes expectations to combat money laundering and terrorist financing.
This module describes expectations and practices relating to capital adequacy.
This module describes expectations for corporate governance.
This module describes expectations for credit risk and counterparty credit risk management.
This module describes expectations for external audit and sets out references related to public disclosure.
This module describes expectations for banks’ internal audit and compliance functions.
This module describes expectations for liquidity risk management.
This module sets out references related to market risk and interest rate risk.
This module describes expectations for the management of operational risk and operational resilience.
This module describes expectations for the management of problem assets and expected credit losses.
This module describes the application of proportionality in prudential regulation and supervision.
This module describes expectations for risk management.
This module describes the nature and application of prudential supervision.