Learning Objectives:

  • Identify the types of third-party risks facing central banks.

  • Apply risk classification methodologies to third-party relationships.

  • Create and maintain a comprehensive third-party inventory.

  • Recognise the importance of materiality in TPRM.

2.1 Types of Third-Party Risks

Third-party relationships expose central banks to a range of risks that must be identified and managed. The MAS TPRM Guidelines require financial institutions to identify and assess the types and levels of risks, and the materiality of potential services provided through a third-party arrangement .

Key Risk Categories:

Cybersecurity Risks: Threats from third-party systems and data breaches. The MAS requires financial institutions to identify and assess cybersecurity threats, operational dependencies, legal and compliance risks, reputational impacts, and concentration risks .

Operational Dependencies: The risk that a third-party failure could disrupt critical central bank operations. Supply chain breaches are now “shareholder events, regulatory triggers, and reputational liabilities” that land squarely on the board agenda .

Compliance and Regulatory Risks: The risk of non-compliance with data protection and privacy laws. The PBOC requires commercial banks to regularly conduct information security assessments on their partnering supply chain information service providers .

Concentration Risks: The risk of over-reliance on a limited number of third-party providers. The ECB Guide emphasises avoiding dependencies on specific vendors, including regular reassessment .

Geopolitical Risks: The risk of exposure to jurisdictions with political or legal risks that could affect service delivery or data security .

2.2 Risk Classification and Materiality

Risk classification is essential for prioritising TPRM efforts. The MAS requires financial institutions to establish criteria to determine the governance and due diligence requirements that they should be subject to . MAS also requires financial institutions to maintain a record of their third-party arrangements and submit a register of third-party arrangements to MAS semi-annually or upon request, minimally including all material third-party arrangements .

Risk Classification Criteria:

  • Criticality to Business Performance: How essential the third-party service is to central bank operations

  • Data Sensitivity: The sensitivity of data shared with the third party

  • Regulatory Impact: The regulatory implications of a third-party failure

  • Concentration: The level of reliance on a single provider

  • Jurisdiction: The location of the third party and applicable legal/regulatory frameworks

The Bank of England identifies its critical vendors as those whose failure or compromise would halt operations, expose regulated data, or trigger a regulatory notification . Most organisations can identify their truly critical dependencies in a list of fewer than twenty .

2.3 Creating and Maintaining a Third-Party Inventory

A comprehensive third-party inventory is essential for effective TPRM. The MAS TPRM Guidelines require financial institutions to create and maintain a register of third-party arrangements . The register should minimally include all material third-party arrangements (including material sub-contractors, where possible) .

Key Elements of a Third-Party Inventory:

  • Vendor Information: Legal name, contact details, and ownership structure

  • Service Description: The nature and scope of services provided

  • Risk Classification: The materiality and risk level of the arrangement

  • Contract Details: Key contract terms, including SLAs and termination clauses

  • Sub-Contractors: Information on material sub-contractors

  • Assessment History: Records of due diligence and ongoing assessments

The Bank of England has focused on identifying critical vendors and maintaining that list accurately as the supply chain changes . The complexity of modern supply chains, combined with growing reliance on open-source software and its downstream dependencies, has created what has been described as a “perfect storm” for systemic cyber risk .

2.4 The Impact of Geopolitical Risk

Geopolitical risk has become a central concern in TPRM. The ECB has emphasised that trade is as much a security issue as an economic one, with economic interdependence now a source of vulnerability to deliberate weaponisation of dependencies . Eurosystem staff have mapped products that are hard to diversify and difficult to substitute, and can stress test the implications of suddenly cutting off supply .

Key Geopolitical Risk Considerations:

  • Supply Chain Dependencies: The ECB has analysed that a sudden 50% drop in supply from geopolitically distant suppliers would reduce manufacturing value added by 2-3% .

  • Security Vulnerabilities: Disruptions or deliberate weaponisation of supply chains can materially reduce manufacturing value added .

  • Strategic Responses: The ECB identifies three distinct strategic responses—independence, indispensability, and diversification .

  • Financial Contagion: Geoeconomic fragmentation requires readiness to limit financial contagion .