Learning Objectives:
-
Understand the due diligence requirements for third-party relationships.
-
Apply due diligence techniques to assess vendor capabilities and risks.
-
Recognise the importance of risk-based due diligence.
-
Develop a structured onboarding process for third-party providers.
3.1 The Purpose of Due Diligence
Due diligence is the process of assessing the capabilities, security posture, and risk profile of a third-party provider before entering into a relationship. The MAS TPRM Guidelines require financial institutions to perform due diligence prior to entering, renegotiating, or renewing the third-party arrangement, and periodically thereafter . Due diligence can involve on-site checks, particularly for material arrangements .
The RBI requires financial, operational, and cybersecurity checks on vendors to be mandatory—including cloud providers, SaaS platforms, and fintech partners [citation:13,15].
Key Due Diligence Objectives:
-
Capability Assessment: Assessing the vendor’s ability to deliver the required services
-
Security Assessment: Assessing the vendor’s security posture and controls
-
Compliance Assessment: Assessing the vendor’s compliance with relevant regulations
-
Financial Assessment: Assessing the vendor’s financial stability
-
Reputational Assessment: Assessing the vendor’s reputation and track record
3.2 Due Diligence Techniques
The MAS provides detailed guidance on due diligence techniques, including:
On-site Checks: For material arrangements, on-site checks are recommended to verify the vendor’s capabilities and controls .
Independent Audits/Expert Assessments: For material arrangements, independent audits or expert assessments are required .
Questionnaire-Based Assessments: The annual vendor questionnaire model—send a spreadsheet, receive a spreadsheet back, file it, repeat next year—was designed for a different era and is increasingly insufficient .
Automated Assessments: Financial institutions should align third-party responses with the control framework chosen by the organisation and create plans for corrective actions and monitoring progress until fully implemented .
The Bank of England has achieved 70% average supplier engagement through a comprehensive approach that includes :
-
Clear communication with suppliers
-
Data validation to ensure accuracy and minimise false positives
-
Regular engagement through webinars and communication channels
3.3 Risk-Based Due Diligence
The MAS TPRM Guidelines adopt a risk-based approach, requiring financial institutions to implement due diligence in a way that is commensurate with the size and complexity of the FI and the nature and materiality of the third-party services .
Risk-Based Due Diligence:
-
High-Risk Relationships: Comprehensive due diligence, including on-site checks and independent audits
-
Medium-Risk Relationships: Standard due diligence, including questionnaire-based assessments
-
Low-Risk Relationships: Limited due diligence, focusing on key risk indicators
Fourth-Party Risk: The MAS extends expectations to material subcontractors, on a “risk-proportionate and best-effort” basis . Financial institutions must understand and mitigate the risks associated with subcontracting .
3.4 The Onboarding Process
The onboarding process integrates due diligence findings into the vendor relationship. The MAS TPRM Guidelines require financial institutions to ensure that the third-party service provider has adequate understanding of the FI’s policies, people, processes, technology, facilities, and interconnections that are needed to provide the service .
Key Onboarding Steps:
-
Contract Negotiation: Address the risks identified at the risk assessment and due diligence stages
-
Service Integration: Ensure the vendor has adequate understanding of the FI’s requirements
-
Access Provisioning: Grant appropriate access to systems and data
-
Training: Provide training to vendor staff on FI policies and procedures
-
Monitoring Setup: Establish monitoring and reporting mechanisms
The Bank of England’s Approach: The Bank of England identified very early in their TPRM work the importance of establishing strong relationships with suppliers . They continuously focus on building trust and collaboration with suppliers through:
-
Regular engagement through webinars and communication channels
-
Clear communication to internal stakeholders and suppliers
-
A ‘one team approach’
-
Establishing the correct points of contact within third parties