Live Updates

Basel Committee publishes principles for the sound management of third-party risk

AI Analysis

The Basel Committee published final principles for the sound management of third-party risk in the banking sector on 2025-12-10. The publication matters because it creates a common prudential baseline for banks and supervisors and explicitly supersedes the Basel/Joint Forum 2005 outsourcing paper for banking-sector purposes.

Key dates

2025-12-10
Basel Committee published the principles for the sound management of third-party risk
2024-10-09 Deadline
Comment deadline for the consultative version of the principles

Suggested considerations

  • Compliance teams may wish to compare existing outsourcing and third-party risk frameworks against the new 12-principle baseline to identify gaps in governance, lifecycle controls, and supervisor-facing documentation.
  • Firms may wish to review board and senior management oversight arrangements for third-party risk to ensure responsibilities, risk appetite, escalation, and reporting are clearly assigned.
  • Banks should consider whether their third-party inventories, risk assessments, due diligence files, contracts, monitoring processes, and exit planning are aligned to a full lifecycle model rather than a narrow outsourcing model.
  • Supervisory relations teams may wish to map the principles against home and host jurisdiction requirements to identify where local rules are already aligned or where additional supervisory engagement may be needed.
  • Operational resilience teams may wish to test whether critical third-party dependencies, including cloud and technology providers, are sufficiently captured in business continuity and termination planning.

What changed

The Basel Committee replaced the older 2005 Joint Forum outsourcing guidance with a new 12-principle framework focused on third-party service provider arrangements in banking. The framework is broader than traditional outsourcing and is designed to cover the larger, more diverse third-party ecosystem created by digitalisation and financial technology. The principles set expectations across the full lifecycle of an arrangement, from governance and risk assessment through due diligence, contracting, monitoring and termination, and they are split between principles for banks and principles for prudential supervisors. The Committee states that the principles are a common baseline and retain flexibility so jurisdictions can align them with local regulatory frameworks. The publication does not d

Compliance impact

The practical impact is broad for banking-sector third-party risk management because the publication updates the prudential benchmark supervisors may use when assessing governance, controls, and resilience. The Committee does not describe legal sanctions, but firms that lag the baseline may face supervisory challenge, remediation expectations, or pressure to strengthen third-party oversight and li

Who is affected

  • Banks
  • Prudential supervisors of banks
  • Internationally active banks
  • Smaller banks subject to national supervisory expectations
  • Banking groups with material third-party service provider arrangements
  • Basel Committee 2005 Joint Forum paper Outsourcing in financial services
  • Basel Committee Principles for the Sound Management of Operational Risk
  • Basel Committee Principles for Operational Resilience

AI-generated analysis. May contain errors or omissions — verify with the original BIS source before acting. Full disclaimer.

What the BIS said

The Basel Committee has published principles for the sound management of third-party risk in the banking sector. The principles establish a common baseline for banks and supervisors for the sound management of third-party risk. The Committee will continue to monitor developments related to the digitalisation of…

Extract from BIS . Read the full notice at the source for the authoritative text.

Relevant Firm Types

Bank
View Original on BIS Back to Feed

Share this update