Learning Objectives:

  • Define third-party risk management and explain its strategic importance for central banks.

  • Trace the evolution from outsourcing to comprehensive third-party risk management.

  • Understand the key principles of effective TPRM frameworks.

  • Recognise the regulatory landscape for TPRM.

1.1 What is Third-Party Risk Management?

Third-Party Risk Management (TPRM) is the systematic process of identifying, assessing, mitigating, and monitoring risks associated with the use of third-party service providers. As financial services become increasingly digitalised and interconnected, the dependency on third-party providers—including cloud service providers, core banking vendors, and outsourced AI systems—has become a key driver of ICT-related risks . The supply chain has moved from a technical concern to a governance imperative, with regulators treating third-party cyber risk as systemic risk, not operational risk [citation:13,15].

Key Principles of TPRM:

Outsource Services, Not Responsibility: Regulated entities remain fully accountable for data security and service outcomes, regardless of outsourcing arrangements. The RBI has made it clear that the regulated entity remains fully responsible for the security of data even when it relies on third parties [citation:13,15].

Board-Level Governance: TPRM is no longer an IT function but a board-level governance priority. The Central Bank of the UAE and the Saudi Central Bank have both issued third-party risk management guidance requiring board-level oversight .

Lifecycle Approach: TPRM must be addressed across the entire lifecycle of the third-party arrangement, from risk assessment and due diligence through contracting, ongoing monitoring, and termination [citation:2,11].

Continuous, Not Point-in-Time: The annual vendor questionnaire model is no longer sufficient in 2026. Continuous monitoring, contractual notification requirements, and defined escalation paths are the expected baseline .

1.2 The Evolution from Outsourcing to Comprehensive TPRM

The regulatory approach to third-party relationships has evolved significantly from a narrow focus on outsourcing to a comprehensive framework covering all third-party services.

The MAS Regulatory Evolution:

The Monetary Authority of Singapore (MAS) has established detailed requirements for managing third-party outsourcing and non-outsourcing relationships . In July 2016, MAS delivered guidelines on outsourcing third-party arrangements. MAS expanded their outsourcing guidance in October 2018, and again in August 2022 with the publication of an information paper, “Operational Risk Management – Management of Outsourcing and Third Party Arrangements” .

In March 2026, MAS released a Consultation Paper on Proposed Guidelines on Third-Party Risk Management (TPRM Guidelines) [citation:2,11]. The TPRM Guidelines will supersede the existing MAS guidelines on outsourcing and expand the application of relevant expectations currently imposed on outsourced services to all third-party services . Unlike the Outsourcing Guidelines, the TPRM Guidelines has a wider scope of application: it will apply not just to financial institutions with outsourcing arrangements, but all financial institutions that rely on third-party services .

1.3 The Regulatory Landscape for TPRM

ECB’s Guide on Outsourcing Cloud Services:

In July 2025, the ECB published its final Guide on outsourcing cloud services to cloud service providers . The Guide does not lay down legally binding requirements but clarifies the expectations the ECB has for banks to comply with DORA requirements. It also provides good practices on effective outsourcing risk management for banks under ECB supervision that use third-party cloud services, based on observed industry practices .

Key areas covered in the Guide include:

  • Governance and risk management

  • Resilience, security, and exit strategies

  • Oversight, monitoring, and audit

  • Data encryption and key management

  • Sub-outsourcing and concentration risk 

MAS TPRM Guidelines (Proposed):

The proposed MAS TPRM Guidelines provide guidance on four key areas :

  1. Creating and maintaining a register of third-party arrangements

  2. An FI’s governance and its third-party risk management and strategy

  3. How an FI should handle its third-party arrangements from the pre-contract stage to termination

  4. Use of sub-contractors

RBI Cybersecurity Guidelines:

The RBI has tightened cybersecurity expectations across banks, NBFCs, and payment system players . Key takeaways include:

  • Outsourced services, not responsibility: the regulated entity remains fully accountable

  • Mandatory due diligence: financial, operational, and cybersecurity checks on vendors

  • Secure contracts: data protection clauses, breach reporting timelines, audit rights, and SLAs

  • Continuous monitoring: security reviews, access monitoring, vulnerability testing, and incident tracking 

EU Cyber Resilience Act:

The EU Cyber Resilience Act introduces fines of up to €15 million or 2.5% of global annual turnover for non-compliance with cybersecurity requirements across software and digital product supply chains .

1.4 The Bank of England’s Approach to TPRM

The Bank of England has developed a comprehensive TPRM service with Orpheus Cyber, delivering a threat-led approach for predictive and actionable cyber risk management . Key elements of the Bank of England’s approach include:

  • 70% average supplier engagement

  • 25% reduction in supply chain cyber risk

  • Continuous monitoring of supplier security posture

  • Actionable cyber risk communication

  • A collaborative, one-team approach with suppliers