Operational Resilience / Outsourcing in International
Operational Resilience / Outsourcing regulatory updates from International.
We track 21 Operational Resilience / Outsourcing updates from International regulators, published by BIS and FSB. The archive covers 13 news items, 6 speeches and 2 consultations. Most recent update: September 2026. Coverage runs from 2025 to 2026.
Roundtable to explore how collaboration efforts between the public and private sectors can be structured and applied to prepare for and manage significant operational disruptions.
Why this matters
This is a news item reporting on an FSB roundtable discussion focused on strengthening operational resilience through public-private collaboration. The content discusses practical steps, relationship-building, lessons learned, and interoperability across sectors and jurisdictions.
CPMI-IOSCO are seeking input from stakeholders on a cyber resilience toolkit for financial market infrastructures (FMIs) and on risks to FMIs from third-party service providers. The Cyber resilience toolkit: practical considerations for FMIs supports FMIs in strengthening their cyber resilience frameworks. The…
Why this matters
This is a formal consultation by CPMI-IOSCO seeking stakeholder input on two interconnected deliverables: a cyber resilience toolkit for FMIs and a discussion paper on third-party service provider risks. The toolkit complements existing PFMI principles and provides practical guidance on operational resilience.
The potential impact of frontier AI on cyber risk is the most immediate concern to the financial system, says FSB Chair, Andrew Bailey.
Why this matters
This is a policy statement from the FSB Chair to G20 authorities identifying frontier AI and cyber risk as priority concerns requiring jurisdictional and institutional response. The letter calls for concrete steps on safe AI deployment and third-party resilience, indicating regulatory intent to develop standards.
In his letter to G20 Finance Ministers and Central Bank Governors, Andrew Bailey, warns that markets remain vulnerable to a potential disorderly correction and cautions on the risks posed by frontier AI models.
Why this matters
This is a speech/letter from the FSB Chair to G20 policymakers flagging frontier AI as an emerging systemic risk to financial stability, particularly through cyber vulnerabilities and market confidence impacts.
In this speech, John Schindler, FSB Secretary General, addresses the importance of international organisations in a shifting geopolitical landscape.
Why this matters
This is a speech by the FSB Secretary General addressing the state of multilateralism in financial regulation. While not a binding rule or consultation, it provides noteworthy regulatory signals about FSB priorities and approach.
In this speech, FSB Secretary General, John Schindler highlights the importance of resolve in resolution planning, emphasising collaboration, preparedness, in maintaining financial system resilience.
Why this matters
This is an informational speech (urgency: null) but carries noteworthy regulatory signals. The FSB Secretary General explicitly announces a strategic review of crisis preparedness and emphasizes a deliberate policy shift from sector-by-sector resolution frameworks to integrated cross-sectoral planning.
At the virtual event, hosted by OMFIF, FSB Deputy Secretary General calls for a debate on the next steps for cross-border payments beyond 2027.
Why this matters
This is an opening remarks speech at a virtual event, not a binding obligation or final rule. However, it carries concrete regulatory signals about the FSB's thinking on cross-border payments policy beyond 2027, including questions about standardization (ISO 20022), stablecoins, regional coordination, and...
In this speech, Dominique Laboureix, Chair of the FSB Resolution Steering Group, discusses the importance of cross-border, cross-sectoral crisis preparedness.
Why this matters
This is a speech by the Chair of the FSB Resolution Steering Group at the ReSolve event, focused on cross-sectoral interconnections in financial stability and crisis management.
Roundtable hosted by the Bank of Spain discusses external audit.
Why this matters
This is a news item reporting on an FSB convened roundtable discussion (not a binding rule, consultation, or enforcement action). The content addresses structural changes in the audit profession driven by technology (AI) and ownership shifts, with implications for audit quality and financial stability.
The Basel Committee on Banking Supervision today published a range of practices report on information and communication technology (ICT) risk management. ICT is a key component of operational risk management, playing a vital role in supporting the broader goal of achieving operational resilience.
Why this matters
This is a Basel Committee publication of a range of practices report (not binding rules, but authoritative guidance) addressing ICT risk management as a component of operational resilience. The content is informational/guidance-focused rather than a consultation or final rule, and targets banks specifically.
Basel Committee publishes report on information and communication technology risk management.
Why this matters
This is a published report from the Basel Committee on Banking Supervision (BCBS) analyzing ICT risk management practices across jurisdictions. The content explicitly addresses operational resilience and ICT/cyber risk in banking.
The Basel Committee has published a report describing a range of observed information and communication technology (ICT) risk management practices across jurisdictions to address non-malicious ICT incidents.
Why this matters
This is a media release announcing publication of a Basel Committee range of practices report on ICT risk management. The report documents observed practices across jurisdictions and is intended as a reference for banks and supervisory authorities.
The Project Agorá prototype demonstrates how tokenisation and programmable technologies can address long-standing inefficiencies in wholesale cross-border payments at scale, while preserving the safety and integrity of settlement in central bank reserves.
Why this matters
This is a press release and research report from the BIS announcing Project Agorá findings on tokenisation for wholesale payments. It is informational and exploratory in nature (explicitly noted as experimental), not a binding obligation or final rule.
The Project Agorá prototype demonstrates how tokenisation and programmable technologies can address long-standing inefficiencies in wholesale cross-border payments at scale, while preserving the safety and integrity of settlement in central bank reserves.
Why this matters
The content is a media release and research report from the BIS Innovation Hub detailing Project Agorá's exploratory findings on tokenised wholesale cross-border payments.
Agrees to publish range of practices report on information and communication technology risk management. Progresses its targeted review of the prudential standard for banks' cryptoasset exposures. Considers targeted updates of its principles on liquidity risk.
Why this matters
This is a Basel Committee press release documenting meeting outcomes and regulatory work in progress. The Committee approved publication of an ICT risk management practices report (addressing operational resilience), is progressing a targeted review of cryptoasset prudential standards, and is considering updates to...
Agrees to publish range of practices report on information and communication technology risk management. Progresses its targeted review of the prudential standard for banks' cryptoasset exposures. Considers targeted updates of its principles on liquidity risk.
Why this matters
This is a media release documenting Basel Committee meeting outcomes. The content supports three primary regulatory initiatives: (1) publication of ICT risk management practices report addressing operational resilience, (2) ongoing targeted review of cryptoasset prudential standards with updates promised later in...
CPMI-IOSCO is seeking input from interested stakeholders on amendments to CCP-related resilience guidance and public quantitative disclosures requirements.
Why this matters
This is a formal consultation by CPMI-IOSCO on proposed amendments to existing CCP resilience guidance (2017) and public quantitative disclosure standards (2015), incorporating proposals from the January 2025 BCBS-CPMI-IOSCO report on initial margin transparency.
Discusses vulnerabilities in government bond-backed repo markets. Discusses progress of a targeted review of the prudential standard for banks' cryptoasset exposures. Announces date and location of the International Conference of Banking Supervisors.
Why this matters
This is a press release announcing Basel Committee meeting outcomes. The text explicitly discusses an expedited review of cryptoasset exposure standards (with update promised later in 2026), approved technical amendments to operational risk standardised approach (publishing March 2026), and vulnerabilities in repo...
As part of its 2025-2026 work programme, the Basel Committee is advancing various supervisory initiatives related to the digitalisation of finance.
AI Analysis
The Basel Committee has published its Principles for the sound management of third-party risk, setting a common baseline for banks and supervisors as firms become more dependent on third-party service providers. The publication matters because it broadens the supervisory lens beyond traditional outsourcing to a wider range of third-party arrangements, with implications for governance, due diligence, contracts, monitoring, and exit planning.
Key dates
2025-12-10
Basel Committee publication date for the Principles for the sound management of third-party risk
Suggested considerations
Compliance teams may wish to map all third-party arrangements against the new lifecycle expectations, including non-traditional outsourcing and intra-group or technology-enabled arrangements.
Firms should consider whether board-approved third-party risk appetite, tolerance for disruption, and reporting lines are documented clearly and align with current governance arrangements.
Banks may wish to review due diligence, contracting, onboarding, monitoring, continuity, and exit procedures to confirm they address the principle-based expectations across the full relationship lifecycle.
Supervisory liaison teams may wish to assess whether concentration risk, critical provider dependencies, and cross-border coordination issues are adequately captured in existing risk registers and escalation frameworks.
What changed
The document sets out 12 principles covering the full third-party service provider lifecycle, divided between bank-facing expectations and supervisor-facing expectations. For banks, the principles cover governance and strategy, board and senior management oversight, risk assessment, due diligence, legally binding contracts, onboarding, ongoing monitoring, business continuity, and termination/exit management.
Compliance impact
The publication is a material supervisory signal rather than a binding rule, but it raises the expected standard for how banks identify, manage, and oversee third-party dependencies. Institutions that rely heavily on external providers may face closer supervisory scrutiny of governance, resilience, and concentration risk, especially where critical services are involved.
The Basel Committee has published principles for the sound management of third-party risk in the banking sector. The principles establish a common baseline for banks and supervisors for the sound management of third-party risk. The Committee will continue to monitor developments related to the digitalisation of…
AI Analysis
The Basel Committee published final principles for the sound management of third-party risk in the banking sector on 2025-12-10. The publication matters because it creates a common prudential baseline for banks and supervisors and explicitly supersedes the Basel/Joint Forum 2005 outsourcing paper for banking-sector purposes.
Key dates
2025-12-10
Basel Committee published the principles for the sound management of third-party risk
2024-10-09 Deadline
Comment deadline for the consultative version of the principles
Suggested considerations
Compliance teams may wish to compare existing outsourcing and third-party risk frameworks against the new 12-principle baseline to identify gaps in governance, lifecycle controls, and supervisor-facing documentation.
Firms may wish to review board and senior management oversight arrangements for third-party risk to ensure responsibilities, risk appetite, escalation, and reporting are clearly assigned.
Banks should consider whether their third-party inventories, risk assessments, due diligence files, contracts, monitoring processes, and exit planning are aligned to a full lifecycle model rather than a narrow outsourcing model.
Supervisory relations teams may wish to map the principles against home and host jurisdiction requirements to identify where local rules are already aligned or where additional supervisory engagement may be needed.
Operational resilience teams may wish to test whether critical third-party dependencies, including cloud and technology providers, are sufficiently captured in business continuity and termination planning.
What changed
The Basel Committee replaced the older 2005 Joint Forum outsourcing guidance with a new 12-principle framework focused on third-party service provider arrangements in banking. The framework is broader than traditional outsourcing and is designed to cover the larger, more diverse third-party ecosystem created by digitalisation and financial technology.
Compliance impact
The practical impact is broad for banking-sector third-party risk management because the publication updates the prudential benchmark supervisors may use when assessing governance, controls, and resilience. The Committee does not describe legal sanctions, but firms that lag the baseline may face supervisory challenge, remediation expectations, or pressure to strengthen third-party oversight and lifecycle controls.
The Basel Committee on Banking Supervision horizon scanning report on banks' interconnections with non-bank financial intermediaries (NBFIs).
Why this matters
This is a published horizon scanning report from the Basel Committee analyzing interconnections between banks and non-bank financial intermediaries. The report describes direct and indirect linkages, discusses risks and vulnerabilities, includes case studies and stylised failure scenarios, and emphasizes data...