Learning Objectives:
-
Understand the key contract provisions required for effective TPRM.
-
Apply service level agreements (SLAs) to monitor third-party performance.
-
Recognise the importance of audit rights and termination clauses.
-
Develop a contract management framework for third-party relationships.
4.1 Key Contract Provisions
The MAS TPRM Guidelines require that contracts address the risks identified at the risk assessment and due diligence stages . Agreements with material third-party arrangements should include a range of key provisions :
Risk Management Provisions:
-
A right to receive information
-
Audit and inspection rights
-
Adverse event reporting
-
FI’s right to ownership, access to, and use of assets
-
Termination rights
Performance Provisions:
-
Key performance benchmarks
-
Framework to modify existing arrangements
-
Provisions necessary to allow FI to exercise effective monitoring and control
Jurisdictional Provisions:
-
Locations, regions, or jurisdictions where the service will be performed
-
Where relevant data will be processed and stored
-
Choice of law and dispute resolution process
Subcontracting Provisions:
-
Subcontracting controls
-
Information on material subcontractors
Complaints:
-
Complaints procedure (if applicable)
The RBI has emphasised that secure contracts are non-negotiable, with data protection clauses, breach reporting timelines, audit rights, and SLAs explicitly documented in every IT outsourcing agreement [citation:13,15].
4.2 Service Level Agreements (SLAs)
SLAs define the expected performance standards for third-party services. The ECB Guide requires that contracts include:
-
Service level objectives
-
Incident response expectations
-
Data access rights
-
Location of data processing
-
Exit strategies
Key SLA Elements:
-
Performance Metrics: Specific, measurable performance indicators
-
Response Times: Defined response times for different types of incidents
-
Escalation Procedures: Clear escalation paths for service failures
-
Reporting: Regular reporting on service performance
-
Remedies: Remedies for service failures, including financial penalties
4.3 Audit Rights and Access
Audit rights are essential for verifying third-party compliance. The MAS TPRM Guidelines require that contracts include audit and inspection rights . The ECB Guide emphasises that institutions must retain the right to access, audit, and inspect the ICT systems and premises of third-party providers .
Key Audit Rights Provisions:
-
Right to Audit: The FI’s right to audit the third-party provider
-
Right to Inspect: The FI’s right to inspect the third-party provider’s systems and premises
-
Right to Access: The FI’s right to access information and data
-
Independent Audits: Board-approved audit frequency for material arrangements
-
Expert Assessments: The right to engage independent experts to conduct assessments
4.4 Termination and Exit Management
Exit strategies are essential for managing the end of third-party relationships. The MAS TPRM Guidelines require financial institutions to maintain exit plans to cater for different plausible termination scenarios . The ECB Guide requires that exit strategies be established for all critical or important cloud services before go-live and include granular plans covering timelines, costs, resource needs, identified alternatives, and transition periods .
Key Exit Strategy Elements:
-
Exit Plans: Detailed plans for terminating the relationship
-
Transition Support: Support for transitioning services to another provider or in-house
-
Data Retrieval: Processes for retrieving data from the third-party provider
-
Data Destruction: Processes for ensuring data is destroyed by the third-party provider
-
Testing: Testing of exit plans periodically
-
Cost Estimates: Realistic cost estimates for exit