Principles for the sound management of third-party risk
AI Analysis
The Basel Committee has published its Principles for the sound management of third-party risk, setting a common baseline for banks and supervisors as firms become more dependent on third-party service providers. The publication matters because it broadens the supervisory lens beyond traditional outsourcing to a wider range of third-party arrangements, with implications for governance, due diligence, contracts, monitoring, and exit planning.
Key dates
- 2025-12-10
- Basel Committee publication date for the Principles for the sound management of third-party risk
Suggested considerations
- Compliance teams may wish to map all third-party arrangements against the new lifecycle expectations, including non-traditional outsourcing and intra-group or technology-enabled arrangements.
- Firms should consider whether board-approved third-party risk appetite, tolerance for disruption, and reporting lines are documented clearly and align with current governance arrangements.
- Banks may wish to review due diligence, contracting, onboarding, monitoring, continuity, and exit procedures to confirm they address the principle-based expectations across the full relationship lifecycle.
- Supervisory liaison teams may wish to assess whether concentration risk, critical provider dependencies, and cross-border coordination issues are adequately captured in existing risk registers and escalation frameworks.
What changed
The document sets out 12 principles covering the full third-party service provider lifecycle, divided between bank-facing expectations and supervisor-facing expectations. For banks, the principles cover governance and strategy, board and senior management oversight, risk assessment, due diligence, legally binding contracts, onboarding, ongoing monitoring, business continuity, and termination/exit management. For supervisors, the principles cover integrating third-party risk into ongoing supervision, identifying concentration and systemic risks from critical providers, and coordinating across sectors and borders. The Basel Committee frames these principles as a common baseline rather than a rigid rulebook, so jurisdictions can adapt implementation to local regulatory frameworks and evolving
Compliance impact
The publication is a material supervisory signal rather than a binding rule, but it raises the expected standard for how banks identify, manage, and oversee third-party dependencies. Institutions that rely heavily on external providers may face closer supervisory scrutiny of governance, resilience, and concentration risk, especially where critical services are involved.
Who is affected
Related regulations
References
AI-generated analysis. May contain errors or omissions — verify with the original BIS source before acting. Full disclaimer.
What the BIS said
As part of its 2025-2026 work programme, the Basel Committee is advancing various supervisory initiatives related to the digitalisation of finance.
Published by BIS . Read the full notice at the source for the authoritative text.