Featured Product

    OSFI Identifies Focus Areas to Strengthen Third-Party Risk Management

    September 08, 2020

    OSFI published the key findings of a study on third-party risk management. The study was conducted in 2019-20 among 55 federally regulated financial institutions, with 47% of them being deposit-taking institutions and the remaining being the insurance institutions. As a result of this study, OSFI has identified five focal points for effective management of third-party risk: risk assessment, monitoring and incident management, data security and access, continuity of critical operations, and cloud risk management. For further insights on the perspectives and work of OSFI in this area, OSFI will soon release a discussion paper on technology risk, which includes a segment on third-party risk.

    The federally regulated financial institutions frequently cite third-party risk as a top or key risk due to the increasing engagement with, and reliance on, third parties. The following are the key insights that OSFI derived from the study on the third-party risk management:

    • Risk Assessment—Prudent risk management involves focusing on the highest risks at certain providers while providing adequate oversight for providers with lower risk profiles. Developing risk management frameworks with a range of risk categories can help federally regulated financial institutions to more effectively manage the risk from third parties.
    • Monitoring and Incident Management—Establishing a process to regularly monitor risks against desired standards and measures can help federally regulated financial institutions to more effectively identify whether and when a third party is creating risk. The results highlight that 36% of the respondents indicated that they maintained a watchlist—that is, a list of third parties identified for enhanced monitoring. Reasons cited to maintain a watchlist include criticality and significance to the operations of a federally regulated financial institution and elevated risks of financial, operational, or reputational damage to the federally regulated financial institution.
    • Data Security and Access—Lack of adequate controls and monitoring of third-party access, storage, and use of federally regulated financial institution information may expose federally regulated financial institutions to higher risk of data breaches and loss of confidentiality. Security risk assessments are the first step in protecting federally regulated financial institution data as these can aid federally regulated financial institutions understanding if the risk is being sufficiently managed by the third party. The results highlight that 83% of the respondents cite information security controls and performance as the top assessment factor during the due diligence phase prior to onboarding a third party. While 86% of the respondents include information security controls and performance in due diligence refreshes, 23% perform real-time security monitoring of third parties.
    • Continuity of Critical Operations—Identifying critical third-party dependencies and conducting joint exercises with these parties can help to develop and reinforce the recovery processes, communication channels, authority levels, and trusted relationships that are necessary to work cohesively and collaboratively through a disruption. There were 17 respondents with the management of critical third parties in scope of the study. The results highlight that 53% of the respondents have business continuity plans, recovery time objectives, and service-level agreements for critical services in place with third parties while 82% have established specific recovery time objectives and recovery point objectives with third parties for critical business services. 
    • Cloud Risk Management—Cloud adoption has moved past proof-of-concept testing and toward an established or emerging practice of assessment and onboarding at federally regulated financial institutions. While managing cloud services is a shared responsibility between the federally regulated financial institution and the cloud service provider, developing cloud-specific standards may enable federally regulated financial institutions to increase interoperability and optimize cloud adoption while operating within the federally regulated financial institution's risk appetite and tolerances. There were eight respondents with cloud risk management in the scope of the study. The results provide data related to cloud adoption challenges, challenges in cloud computing operations, and cloud availability and exit strategy.

     

    Related Link: Results of Study (PDF)

     

    Keywords: Americas, Canada, Banking, Insurance, Third-Party Risk, Cloud Computing, Outsourcing Arrangements, Technology Risk, Fintech, Regtech

    Related Articles
    News

    EU Agencies Update LCR Rule and Macro-Prudential Policy Recommendation

    The European Commission (EC) published the Delegated Regulation 2022/786 with regard to the liquidity coverage requirements for credit institutions under the Capital Requirements Regulation (CRR).

    May 23, 2022 WebPage Regulatory News
    News

    EBA Publishes Regulatory Standards to Identify Shadow Banking Entities

    The European Banking Authority (EBA) published the final draft regulatory technical standards specifying the criteria to identify shadow banking entities for the purposes of reporting large exposures.

    May 23, 2022 WebPage Regulatory News
    News

    OSFI Discusses Benchmark Rate Transition, Sets Out Work Priorities

    The Office of the Superintendent of Financial Institutions (OSFI) published the strategic plan for 2022-2025 and the departmental plan for 2022-23.

    May 17, 2022 WebPage Regulatory News
    News

    EBA Proposes Standards to Support Secondary NPL Markets

    The European Banking Authority (EBA) is consulting, until August 31, 2022, on the draft implementing technical standards specifying requirements for the information that sellers of non-performing loans (NPLs) shall provide to prospective buyers.

    May 17, 2022 WebPage Regulatory News
    News

    EU Confirms Agreement on Rules on Cybersecurity and Banking Resolution

    The European Council and the Parliament reached an agreement on the revised Directive on security of network and information systems (NIS2 Directive).

    May 13, 2022 WebPage Regulatory News
    News

    EBA Issues Standards for Crowdfunding Service Providers Under ECSPR

    The European Banking Authority (EBA) published the final draft regulatory technical standards specifying information that crowdfunding service providers shall provide to investors on the calculation of credit scores and prices of crowdfunding offers.

    May 13, 2022 WebPage Regulatory News
    News

    EU to Amend Credit Risk Adjustment Rules; ESAs Submit Queries on SFDR

    The European Council published a draft Commission Delegated Regulation to amend the regulatory technical standards on specification of the calculation of specific and general credit risk adjustments.

    May 13, 2022 WebPage Regulatory News
    News

    EU Confirms Agreement on Rules on Cybersecurity and Banking Resolution

    The European Securities and Markets Authority (ESMA) published a paper that examines the systemic risk posed by increasing use of cloud services, along with the potential policy options to mitigate this risk.

    May 12, 2022 WebPage Regulatory News
    News

    MAS Amends Notice 635 and Issues Second Proposal on Green Taxonomy

    The Monetary Authority of Singapore (MAS) published amendments to Notice 635, which sets out requirements that a bank in Singapore has to comply with when granting an unsecured non-card credit facility to individuals.

    May 12, 2022 WebPage Regulatory News
    News

    EC Consults on PSD2 and Open Finance; EU Reaches Agreement on DORA

    The European Commission (EC) published a public consultation on the review of revised payment services directive (PSD2) and open finance.

    May 11, 2022 WebPage Regulatory News
    RESULTS 1 - 10 OF 8201