Compliance · Singapore

The vendor risk blind spot in MAS TRM outsourcing

Outsourcing IT doesn't outsource the responsibility. Here's what MAS's Technology Risk Management Guidelines expect before, during and after you appoint a vendor — and the gap most institutions miss.

Quick answer A financial institution remains accountable for technology risk even when a vendor does the technical work. Due diligence that happens once, at signing, and is never revisited is the most common gap.

Outsourcing doesn't outsource the responsibility

A financial institution that outsources IT infrastructure, hosting or support to a vendor remains accountable for the technology risk that arrangement creates. That's the starting principle behind how MAS's Technology Risk Management Guidelines treat outsourcing — the guidelines set out expectations for governance and oversight that don't disappear just because a third party is doing the technical work. Always check MAS's current published Guidelines directly for the authoritative, up-to-date wording rather than relying on a summary, including this one.

What MAS expects before you sign

Due diligence on a technology vendor, under the Guidelines' broader risk management principles, is expected to go beyond price and feature comparison:

Area to checkWhat you're really asking
Security postureWould this vendor meet our own internal bar?
Sub-outsourcingDo they outsource parts of the service further, and to whom?
Incident historyHow have they actually handled problems before?
Resilience & recoveryDo their own DR/BC commitments meet what we need, not just what they offer?

Ongoing oversight, not a one-time exercise

The blind spot: due diligence done once, at signing, and never revisited. Vendor risk changes over time — staff changes, sub-outsourcing changes, incidents at the vendor, or the vendor's own risk posture drifting.

Ongoing oversight means periodic reassessment, a clear escalation path if the vendor has an incident, and visibility into the vendor's own controls on a continuing basis — not just a signed contract filed away.

Planning your exit before you need it

Concentration and exit risk are part of what a sound outsourcing arrangement should address from the outset: what happens if the vendor fails, is acquired, or the relationship needs to end quickly?

  • Is data portability confirmed and tested, not just promised?
  • Are realistic transition timelines documented?
  • Can critical functions continue during a transition, or does everything stop?

A workable exit plan should exist before it's needed, not be improvised under pressure.

Where this overlaps with your own gap assessment

Vendor oversight is one part of a broader TRM posture — it doesn't replace the institution's own internal controls, and a strong vendor doesn't substitute for weak internal resilience planning. The two should be assessed together. If your institution's own disaster recovery and continuity planning hasn't been reviewed alongside vendor arrangements, that's worth doing next — see why "we have backups" isn't a business continuity plan for the distinction that trips up a lot of otherwise well-run organisations.

Related service

MAS TRM Compliance — gap assessments and ongoing support for financial institutions and their technology vendors.

FAQ

Questions, answered

Appointing or reviewing an IT vendor?

Book a free MAS TRM consultation and we'll help you think through the questions your outsourcing arrangement actually needs answered.