Learning Objectives:
-
Understand the requirements for ongoing monitoring of third-party relationships.
-
Apply continuous monitoring techniques to detect emerging risks.
-
Recognise the importance of periodic reviews and assessments.
-
Develop an incident response framework for third-party incidents.
5.1 The Importance of Ongoing Monitoring
Ongoing monitoring is essential for maintaining visibility of third-party risk. The MAS TPRM Guidelines require financial institutions to ensure that the third-party service provider has adequate understanding of the FI’s policies, people, processes, technology, facilities, and interconnections that are needed to provide the service . Financial institutions must also implement appropriate measures to monitor and manage concentration risks .
The RBI requires ongoing supervision of vendors: security reviews, access monitoring, vulnerability testing, and incident tracking [citation:13,15]. The annual vendor questionnaire model is no longer sufficient in 2026—continuous monitoring, contractual notification requirements, and defined escalation paths are the expected baseline .
Key Monitoring Objectives:
-
Compliance Verification: Verifying that the third party continues to comply with contractual obligations
-
Risk Detection: Detecting changes in the third party’s risk profile
-
Performance Monitoring: Monitoring the third party’s performance against SLAs
-
Incident Detection: Detecting security incidents involving the third party
5.2 Continuous Monitoring Techniques
The MAS TPRM Guidelines require financial institutions to implement continuous monitoring systems that track changes in third-party operations, compliance status, cybersecurity posture, etc. . Key techniques include:
Cybersecurity Monitoring: The Bank of England uses threat-led monitoring of supplier security posture . This includes:
-
Identifying and alerting on vulnerabilities
-
Prioritising suppliers with the highest threat and vulnerability exposure
-
Validating data to minimise false positives
Performance Monitoring: The MAS requires monitoring of service level agreements (SLAs) and key performance benchmarks [citation:2,14].
Regulatory Compliance Checks: Regular checks to identify if third-party providers are compliant with relevant regulations and guidelines .
Dynamic Risk Assessments: Assessments that evolve with changes in the business environment, regulatory landscape, and operational status of third-party providers .
5.3 Periodic Reviews and Assessments
The MAS TPRM Guidelines require periodic due diligence and independent audits/expert assessments for material arrangements . The Bank of England’s approach includes :
Periodic Reviews:
-
Regular reviews of supplier security posture
-
Validation of data to ensure accuracy
-
Assessment of supplier engagement and collaboration
Incident Reporting:
-
Adverse event reporting requirements in contracts
-
Incident notification to MAS as soon as possible for widespread or material impacts
5.4 Incident Response for Third-Party Incidents
The MAS TPRM Guidelines require financial institutions to maintain incident response plans to handle operational disruptions, including reporting mechanisms . Key elements include:
Detection:
-
Continuous monitoring to detect third-party incidents
-
Contractual notification requirements for third-party incidents
Response:
-
Defined escalation paths for third-party incidents
-
Coordination with third-party providers during incidents
Recovery:
-
Business continuity plans for third-party service disruptions
-
Exit strategies for terminating relationships if necessary
Reporting:
-
MAS notification of adverse developments that have widespread impact or materially impact the FI’s service to its customers