Learning Objectives:

  • Understand the requirements for ongoing monitoring of third-party relationships.

  • Apply continuous monitoring techniques to detect emerging risks.

  • Recognise the importance of periodic reviews and assessments.

  • Develop an incident response framework for third-party incidents.

5.1 The Importance of Ongoing Monitoring

Ongoing monitoring is essential for maintaining visibility of third-party risk. The MAS TPRM Guidelines require financial institutions to ensure that the third-party service provider has adequate understanding of the FI’s policies, people, processes, technology, facilities, and interconnections that are needed to provide the service . Financial institutions must also implement appropriate measures to monitor and manage concentration risks .

The RBI requires ongoing supervision of vendors: security reviews, access monitoring, vulnerability testing, and incident tracking [citation:13,15]. The annual vendor questionnaire model is no longer sufficient in 2026—continuous monitoring, contractual notification requirements, and defined escalation paths are the expected baseline .

Key Monitoring Objectives:

  • Compliance Verification: Verifying that the third party continues to comply with contractual obligations

  • Risk Detection: Detecting changes in the third party’s risk profile

  • Performance Monitoring: Monitoring the third party’s performance against SLAs

  • Incident Detection: Detecting security incidents involving the third party

5.2 Continuous Monitoring Techniques

The MAS TPRM Guidelines require financial institutions to implement continuous monitoring systems that track changes in third-party operations, compliance status, cybersecurity posture, etc. . Key techniques include:

Cybersecurity Monitoring: The Bank of England uses threat-led monitoring of supplier security posture . This includes:

  • Identifying and alerting on vulnerabilities

  • Prioritising suppliers with the highest threat and vulnerability exposure

  • Validating data to minimise false positives 

Performance Monitoring: The MAS requires monitoring of service level agreements (SLAs) and key performance benchmarks [citation:2,14].

Regulatory Compliance Checks: Regular checks to identify if third-party providers are compliant with relevant regulations and guidelines .

Dynamic Risk Assessments: Assessments that evolve with changes in the business environment, regulatory landscape, and operational status of third-party providers .

5.3 Periodic Reviews and Assessments

The MAS TPRM Guidelines require periodic due diligence and independent audits/expert assessments for material arrangements . The Bank of England’s approach includes :

Periodic Reviews:

  • Regular reviews of supplier security posture

  • Validation of data to ensure accuracy

  • Assessment of supplier engagement and collaboration

Incident Reporting:

  • Adverse event reporting requirements in contracts 

  • Incident notification to MAS as soon as possible for widespread or material impacts 

5.4 Incident Response for Third-Party Incidents

The MAS TPRM Guidelines require financial institutions to maintain incident response plans to handle operational disruptions, including reporting mechanisms . Key elements include:

Detection:

  • Continuous monitoring to detect third-party incidents

  • Contractual notification requirements for third-party incidents

Response:

  • Defined escalation paths for third-party incidents

  • Coordination with third-party providers during incidents

Recovery:

  • Business continuity plans for third-party service disruptions

  • Exit strategies for terminating relationships if necessary

Reporting:

  • MAS notification of adverse developments that have widespread impact or materially impact the FI’s service to its customers