Learning Objectives:

  • Understand the key contract provisions required for effective TPRM.

  • Apply service level agreements (SLAs) to monitor third-party performance.

  • Recognise the importance of audit rights and termination clauses.

  • Develop a contract management framework for third-party relationships.

4.1 Key Contract Provisions

The MAS TPRM Guidelines require that contracts address the risks identified at the risk assessment and due diligence stages . Agreements with material third-party arrangements should include a range of key provisions :

Risk Management Provisions:

  • A right to receive information

  • Audit and inspection rights

  • Adverse event reporting

  • FI’s right to ownership, access to, and use of assets

  • Termination rights

Performance Provisions:

  • Key performance benchmarks

  • Framework to modify existing arrangements

  • Provisions necessary to allow FI to exercise effective monitoring and control

Jurisdictional Provisions:

  • Locations, regions, or jurisdictions where the service will be performed

  • Where relevant data will be processed and stored

  • Choice of law and dispute resolution process

Subcontracting Provisions:

  • Subcontracting controls

  • Information on material subcontractors

Complaints:

  • Complaints procedure (if applicable) 

The RBI has emphasised that secure contracts are non-negotiable, with data protection clauses, breach reporting timelines, audit rights, and SLAs explicitly documented in every IT outsourcing agreement [citation:13,15].

4.2 Service Level Agreements (SLAs)

SLAs define the expected performance standards for third-party services. The ECB Guide requires that contracts include:

  • Service level objectives

  • Incident response expectations

  • Data access rights

  • Location of data processing

  • Exit strategies 

Key SLA Elements:

  • Performance Metrics: Specific, measurable performance indicators

  • Response Times: Defined response times for different types of incidents

  • Escalation Procedures: Clear escalation paths for service failures

  • Reporting: Regular reporting on service performance

  • Remedies: Remedies for service failures, including financial penalties

4.3 Audit Rights and Access

Audit rights are essential for verifying third-party compliance. The MAS TPRM Guidelines require that contracts include audit and inspection rights . The ECB Guide emphasises that institutions must retain the right to access, audit, and inspect the ICT systems and premises of third-party providers .

Key Audit Rights Provisions:

  • Right to Audit: The FI’s right to audit the third-party provider

  • Right to Inspect: The FI’s right to inspect the third-party provider’s systems and premises

  • Right to Access: The FI’s right to access information and data

  • Independent Audits: Board-approved audit frequency for material arrangements 

  • Expert Assessments: The right to engage independent experts to conduct assessments

4.4 Termination and Exit Management

Exit strategies are essential for managing the end of third-party relationships. The MAS TPRM Guidelines require financial institutions to maintain exit plans to cater for different plausible termination scenarios . The ECB Guide requires that exit strategies be established for all critical or important cloud services before go-live and include granular plans covering timelines, costs, resource needs, identified alternatives, and transition periods .

Key Exit Strategy Elements:

  • Exit Plans: Detailed plans for terminating the relationship

  • Transition Support: Support for transitioning services to another provider or in-house

  • Data Retrieval: Processes for retrieving data from the third-party provider

  • Data Destruction: Processes for ensuring data is destroyed by the third-party provider

  • Testing: Testing of exit plans periodically

  • Cost Estimates: Realistic cost estimates for exit