Key dates
- 2025-12-10
- Basel Committee publication date for the Principles for the sound management of third-party risk
Suggested considerations
- Compliance teams may wish to map all third-party arrangements against the new lifecycle expectations, including non-traditional outsourcing and intra-group or technology-enabled arrangements.
- Firms should consider whether board-approved third-party risk appetite, tolerance for disruption, and reporting lines are documented clearly and align with current governance arrangements.
- Banks may wish to review due diligence, contracting, onboarding, monitoring, continuity, and exit procedures to confirm they address the principle-based expectations across the full relationship lifecycle.
- Supervisory liaison teams may wish to assess whether concentration risk, critical provider dependencies, and cross-border coordination issues are adequately captured in existing risk registers and escalation frameworks.
What changed
The document sets out 12 principles covering the full third-party service provider lifecycle, divided between bank-facing expectations and supervisor-facing expectations. For banks, the principles cover governance and strategy, board and senior management oversight, risk assessment, due diligence, legally binding contracts, onboarding, ongoing monitoring, business continuity, and termination/exit management.
Compliance impact
The publication is a material supervisory signal rather than a binding rule, but it raises the expected standard for how banks identify, manage, and oversee third-party dependencies. Institutions that rely heavily on external providers may face closer supervisory scrutiny of governance, resilience, and concentration risk, especially where critical services are involved.