Learning Objectives:
-
Explain the risks associated with third-party relationships.
-
Understand vendor risk assessment and due diligence.
-
Describe cloud security and outsourcing risk management.
6.1 The Importance of Third-Party Risk Management
Financial institutions increasingly rely on third-party providers for technology services, cloud computing, and specialised functions. Whether financial institutions contract with third-party providers for computer services such as Internet banking, or maintain computer services in-house, bank management is responsible for ensuring that systems and data are protected . The FFIEC provides extensive guidance on third-party risk management .
6.2 Vendor Risk Assessment and Due Diligence
When institutions contract with third-party providers, they should have a sound oversight program . Key practices include:
-
Conducting sufficient analysis of the provider’s security program .
-
Understanding how the provider uses available risk assessment tools and practices.
-
Obtaining copies of independent penetration tests run against the provider’s system.
-
Reviewing security-related clauses in contracts that define responsibilities for data confidentiality, system security, and notification procedures in the event of data or system compromise .
6.3 Cloud Security and Outsourcing
Cloud computing introduces specific security considerations. The FFIEC and other regulatory bodies provide joint statements on risk management for cloud computing services . Key considerations include:
-
Evaluating the cloud provider’s security certifications and controls.
-
Understanding data residency and jurisdictional requirements.
-
Maintaining visibility into security operations in the cloud environment.
-
Establishing clear responsibilities for security between the bank and cloud provider.