Learning Objectives:
-
Understand the emerging threats in TPRM.
-
Analyse the future trends in third-party risk management.
-
Recognise the role of AI and automation in TPRM.
-
Prepare for the evolving regulatory landscape.
8.1 Emerging Threats in TPRM
AI-Enabled Attacks: Frontier AI models are increasing the severity, scale, and sophistication of cyber threats, requiring financial institutions and regulators to strengthen their collective response. The ECB’s July 2026 mandate requires eurozone banks to have plans in place by 31 October to address AI-enabled cyber threats capable of disrupting financial services .
Quantum Computing: Quantum computers, should they reach sufficient size and power, may be able to break the encryption schemes widely used today to secure financial transactions, communication, and data . This makes quantum computing one of the most significant cybersecurity threats facing the financial system.
Supply Chain Attacks:Â Software supply chain attacks are increasing and represent a significant vulnerability for central banks. A single compromised package can cascade into credential theft, cloud compromise, malicious code deployment, and customer-facing service disruption.
8.2 Future Trends in TPRM
Board-Level Governance: Supply chain security has formally shifted from an IT concern to a board-level governance priority . The CBUAE and SAMA have both issued TPRM guidance requiring board-level oversight .
Continuous Monitoring: The annual vendor questionnaire model is no longer fit for purpose in 2026. Continuous monitoring, contractual notification requirements, and defined escalation paths are the expected baseline .
Automated TPRM: The MAS requires continuous monitoring systems that track changes in third-party operations, compliance status, and cybersecurity posture . AI and automation will increasingly be used to manage TPRM at scale.
Regulatory Harmonisation: The ECB Guide clarifies that the Guide does not introduce new rules or requirements over and above those currently imposed by DORA, but instead clarifies expectations and provides good practices . This reflects a trend toward harmonising TPRM requirements across jurisdictions.
8.3 The Role of AI and Automation in TPRM
AI and automation are increasingly being used to enhance TPRM capabilities:
AI-Enabled Threat Intelligence: The ECB expects banks to strengthen monitoring, detection, and AI-enabled defensive capabilities . AI can help identify and assess third-party risks more effectively.
Automated Monitoring: Automated systems can continuously monitor third-party security posture, identifying vulnerabilities and threats in real-time. The Bank of England uses Orpheus to monitor suppliers’ security posture and communicate valid cyber risk issues in an actionable way .
Data Validation: The Bank of England and Orpheus use a rigorous data validation process that leverages automated tooling in addition to analyst verification to minimise the occurrence of false positives .
8.4 Evolving Regulatory Landscape
MAS TPRM Guidelines:Â The proposed MAS TPRM Guidelines expand the scope of TPRM from outsourcing to all third-party services, reflecting the growing recognition of TPRM as a comprehensive risk management discipline [citation:2,11].
ECB Cloud Guide:Â The ECB Guide clarifies supervisory expectations for cloud outsourcing, providing good practices on effective outsourcing risk management for banks under ECB supervision that use third-party cloud services [citation:5,10].
RBI Cybersecurity Guidelines:Â The RBI has tightened cybersecurity expectations across banks, NBFCs, and payment system players, with a significant shift around third-party/vendor risk [citation:13,15].
EU Cyber Resilience Act: The EU Cyber Resilience Act introduces significant fines for non-compliance with cybersecurity requirements across software and digital product supply chains .
UCITS and AIFMD Requirements: The FCA’s key priorities for 2026 include the strengthening of firms’ operational resilience, including by improving oversight of third-party and technology risk .