Live Updates

Principles for the sound management of third-party risk

AI Analysis

The Basel Committee has published its Principles for the sound management of third-party risk, setting a common baseline for banks and supervisors as firms become more dependent on third-party service providers. The publication matters because it broadens the supervisory lens beyond traditional outsourcing to a wider range of third-party arrangements, with implications for governance, due diligence, contracts, monitoring, and exit planning.

Key dates

2025-12-10
Basel Committee publication date for the Principles for the sound management of third-party risk

Suggested considerations

  • Compliance teams may wish to map all third-party arrangements against the new lifecycle expectations, including non-traditional outsourcing and intra-group or technology-enabled arrangements.
  • Firms should consider whether board-approved third-party risk appetite, tolerance for disruption, and reporting lines are documented clearly and align with current governance arrangements.
  • Banks may wish to review due diligence, contracting, onboarding, monitoring, continuity, and exit procedures to confirm they address the principle-based expectations across the full relationship lifecycle.
  • Supervisory liaison teams may wish to assess whether concentration risk, critical provider dependencies, and cross-border coordination issues are adequately captured in existing risk registers and escalation frameworks.

What changed

The document sets out 12 principles covering the full third-party service provider lifecycle, divided between bank-facing expectations and supervisor-facing expectations. For banks, the principles cover governance and strategy, board and senior management oversight, risk assessment, due diligence, legally binding contracts, onboarding, ongoing monitoring, business continuity, and termination/exit management. For supervisors, the principles cover integrating third-party risk into ongoing supervision, identifying concentration and systemic risks from critical providers, and coordinating across sectors and borders. The Basel Committee frames these principles as a common baseline rather than a rigid rulebook, so jurisdictions can adapt implementation to local regulatory frameworks and evolving

Compliance impact

The publication is a material supervisory signal rather than a binding rule, but it raises the expected standard for how banks identify, manage, and oversee third-party dependencies. Institutions that rely heavily on external providers may face closer supervisory scrutiny of governance, resilience, and concentration risk, especially where critical services are involved.

Who is affected

  • Banks
  • Bank supervisors
  • Third-party service providers to banks
  • Critical service providers supporting banking operations
  • Basel Committee operational risk guidance
  • Basel Committee outsourcing principles
  • DORA

AI-generated analysis. May contain errors or omissions — verify with the original BIS source before acting. Full disclaimer.

What the BIS said

As part of its 2025-2026 work programme, the Basel Committee is advancing various supervisory initiatives related to the digitalisation of finance.

Published by BIS . Read the full notice at the source for the authoritative text.

Relevant Firm Types

BankFintechAll Firms
View Original on BIS Back to Feed

Share this update