Basel Committee publishes principles for the sound management of third-party risk
AI Analysis
The Basel Committee published final principles for the sound management of third-party risk in the banking sector on 2025-12-10. The publication matters because it creates a common prudential baseline for banks and supervisors and explicitly supersedes the Basel/Joint Forum 2005 outsourcing paper for banking-sector purposes.
Key dates
- 2025-12-10
- Basel Committee published the principles for the sound management of third-party risk
- 2024-10-09 Deadline
- Comment deadline for the consultative version of the principles
Suggested considerations
- Compliance teams may wish to compare existing outsourcing and third-party risk frameworks against the new 12-principle baseline to identify gaps in governance, lifecycle controls, and supervisor-facing documentation.
- Firms may wish to review board and senior management oversight arrangements for third-party risk to ensure responsibilities, risk appetite, escalation, and reporting are clearly assigned.
- Banks should consider whether their third-party inventories, risk assessments, due diligence files, contracts, monitoring processes, and exit planning are aligned to a full lifecycle model rather than a narrow outsourcing model.
- Supervisory relations teams may wish to map the principles against home and host jurisdiction requirements to identify where local rules are already aligned or where additional supervisory engagement may be needed.
- Operational resilience teams may wish to test whether critical third-party dependencies, including cloud and technology providers, are sufficiently captured in business continuity and termination planning.
What changed
The Basel Committee replaced the older 2005 Joint Forum outsourcing guidance with a new 12-principle framework focused on third-party service provider arrangements in banking. The framework is broader than traditional outsourcing and is designed to cover the larger, more diverse third-party ecosystem created by digitalisation and financial technology. The principles set expectations across the full lifecycle of an arrangement, from governance and risk assessment through due diligence, contracting, monitoring and termination, and they are split between principles for banks and principles for prudential supervisors. The Committee states that the principles are a common baseline and retain flexibility so jurisdictions can align them with local regulatory frameworks. The publication does not d
Compliance impact
The practical impact is broad for banking-sector third-party risk management because the publication updates the prudential benchmark supervisors may use when assessing governance, controls, and resilience. The Committee does not describe legal sanctions, but firms that lag the baseline may face supervisory challenge, remediation expectations, or pressure to strengthen third-party oversight and li
Who is affected
Related regulations
References
AI-generated analysis. May contain errors or omissions — verify with the original BIS source before acting. Full disclaimer.
What the BIS said
The Basel Committee has published principles for the sound management of third-party risk in the banking sector. The principles establish a common baseline for banks and supervisors for the sound management of third-party risk. The Committee will continue to monitor developments related to the digitalisation of…
Extract from BIS . Read the full notice at the source for the authoritative text.