Learning Objectives:

  • Explain the risks associated with third-party relationships.

  • Understand vendor risk assessment and due diligence.

  • Describe cloud security and outsourcing risk management.

6.1 The Importance of Third-Party Risk Management

Financial institutions increasingly rely on third-party providers for technology services, cloud computing, and specialised functions. Whether financial institutions contract with third-party providers for computer services such as Internet banking, or maintain computer services in-house, bank management is responsible for ensuring that systems and data are protected . The FFIEC provides extensive guidance on third-party risk management .

6.2 Vendor Risk Assessment and Due Diligence

When institutions contract with third-party providers, they should have a sound oversight program . Key practices include:

  • Conducting sufficient analysis of the provider’s security program .

  • Understanding how the provider uses available risk assessment tools and practices.

  • Obtaining copies of independent penetration tests run against the provider’s system.

  • Reviewing security-related clauses in contracts that define responsibilities for data confidentiality, system security, and notification procedures in the event of data or system compromise .

6.3 Cloud Security and Outsourcing

Cloud computing introduces specific security considerations. The FFIEC and other regulatory bodies provide joint statements on risk management for cloud computing services . Key considerations include:

  • Evaluating the cloud provider’s security certifications and controls.

  • Understanding data residency and jurisdictional requirements.

  • Maintaining visibility into security operations in the cloud environment.

  • Establishing clear responsibilities for security between the bank and cloud provider.