Authors
On July 9, 2024, the Basel Committee on Banking Supervision (BCBS) issued for comment their “Principles for the sound management of third-party risk”. The 12 proposed principles outlined in the document are intended to supersede those issued in their 2005 Joint Forum paper, Outsourcing in Financial Services.
BCBS’s 12 principles seek to provide global consensus on the key risks and mitigation tactics to be used by banks in relation to their third-party arrangements. In Canada, the Office of the Superintendent of Financial Institutions (OSFI) has released a number of guidelines which offer similar guidance for federally regulated financial institutions (FRFIs) in relation to third-party arrangements (Guideline B10); technology and cyber risk management (Guideline B13); operational risk management (Guideline E-21); corporate governance guideline (Corporate Governance Guideline); and supervisory framework (Supervisory Framework).
This bulletin confirms the key similarities between BCBS’s document and OSFI’s requirements, as shown in the chart below. The approach taken in both OSFI’s Guideline B10 and BCBS’s principles reflects that FRFIs should approach their third-party arrangements following a comprehensive review of the risks unique to the FRFI, the third-party and the arrangement itself, and implement mitigation measures in accordance with the assessed risks.
Principle |
Summary of BCBS Principle |
Comparison to OSFI’s requirements |
1 |
Responsibility for the oversight of all third-party service providers (TPSPs) is in the hands of the Board, who should approve a clear strategy for TPSP arrangements within the FRFI’s risk appetite. |
OSFI assigns responsibility to the Board for the FRFI’s overall business strategy and setting the FRFI’s risk appetite, which will, in practice, include arrangements with third parties1. |
2 |
The Board should ensure that senior management implements the third-party risk management framework, including reporting on performance and assessing and mitigating risks. |
OSFI makes clear that it is the role of senior management to implement the decisions of the Board, which includes ensuring that policies are adhered to2. |
3 |
FRFIs should perform a comprehensive risk assessment to evaluate and manage identified and potential risks throughout a TPSP arrangement. |
OSFI identifies performing a comprehensive risk assessment as outcomes 2 and 5 of Guideline B10’s objectives. In addition, this is identical to B10’s principle 33. |
4 |
FRFIs should conduct due diligence on prospective TPSPs. |
This is identical to B10’s principle 44. |
5 |
TPSPs should be governed by legally binding written contracts that clearly describe rights and obligations. |
This is identical to B10’s principle 6; however, OSFI includes practical guidance on what to do when this is not feasible in Section 3.2 of B105. |
6 |
FRFIs should dedicate sufficient resources to support a TPSP arrangement. |
OSFI makes clear that it is the role of senior management and the Board to mandate resources and budgets for oversight responsibilities, which will, in practice, include the oversight of TPSPs6. |
7 |
FRFIs should assess, monitor, and respond to the performance, risks, and criticality of TPSP arrangements and report to senior management on an ongoing basis. |
This is identical to B10’s principles 5 and 107. |
8 |
FRFIs should maintain robust business continuity management. |
This is identical to B10’s principle 98. |
9 |
FRFIs should maintain exit plans for the termination of TPSP arrangements. |
This is encompassed within B10’s principle 9 as set out in Section 2.3.5 of B109. |
10 |
Supervisors should consider third-party risk management as an integral part of ongoing assessment of FRFIs’ operational resilience. |
This is addressed in OSFI’s Guidelines E-21 (Principle 2)10 and B10 (Outcomes 2 and 5)11 as a concern for FRFI’s to address; however, OSFI’s Supervisory Framework (Operational Resilience)12 addresses the key role supervisors play in overall risk management. |
11 |
Supervisors should analyze potential systemic risks posed by the concentration of one or multiple TPSPs. |
This is encompassed within OSFI’s Guidelines B10 (Principle 4 as set out in Section 2.2.3)13 and Supervisory Framework (Operational Resilience)14. |
12 |
Supervisors should coordinate and communicate across sectors and borders to monitor systemic risks posed by critical TPSPs. |
Requirements that FRFI’s monitor concentration risk within the FRFI and the banking sector are encompassed within B10’s principle 4 as set out in Section 2.2.3 of B1015. However, B10 does not require coordination and communication across other sectors and borders. OSFI’s Supervisory Framework (Supervisory Reporting)16 does prescribe communication with provincial regulators and, where there is a memorandum of understanding, foreign regulators. |
To discuss these issues, please contact the author(s).
This publication is a general discussion of certain legal and related developments and should not be relied upon as legal advice. If you require legal advice, we would be pleased to discuss the issues in this publication with you, in the context of your particular circumstances.
For permission to republish this or any other publication, contact Janelle Weed.
© 2024 by Torys LLP.
All rights reserved.