Outsourcing IT doesn't outsource the responsibility. Here's what MAS's Technology Risk Management Guidelines expect before, during and after you appoint a vendor — and the gap most institutions miss.
A financial institution that outsources IT infrastructure, hosting or support to a vendor remains accountable for the technology risk that arrangement creates. That's the starting principle behind how MAS's Technology Risk Management Guidelines treat outsourcing — the guidelines set out expectations for governance and oversight that don't disappear just because a third party is doing the technical work. Always check MAS's current published Guidelines directly for the authoritative, up-to-date wording rather than relying on a summary, including this one.
Due diligence on a technology vendor, under the Guidelines' broader risk management principles, is expected to go beyond price and feature comparison:
| Area to check | What you're really asking |
|---|---|
| Security posture | Would this vendor meet our own internal bar? |
| Sub-outsourcing | Do they outsource parts of the service further, and to whom? |
| Incident history | How have they actually handled problems before? |
| Resilience & recovery | Do their own DR/BC commitments meet what we need, not just what they offer? |
Ongoing oversight means periodic reassessment, a clear escalation path if the vendor has an incident, and visibility into the vendor's own controls on a continuing basis — not just a signed contract filed away.
Concentration and exit risk are part of what a sound outsourcing arrangement should address from the outset: what happens if the vendor fails, is acquired, or the relationship needs to end quickly?
A workable exit plan should exist before it's needed, not be improvised under pressure.
Vendor oversight is one part of a broader TRM posture — it doesn't replace the institution's own internal controls, and a strong vendor doesn't substitute for weak internal resilience planning. The two should be assessed together. If your institution's own disaster recovery and continuity planning hasn't been reviewed alongside vendor arrangements, that's worth doing next — see why "we have backups" isn't a business continuity plan for the distinction that trips up a lot of otherwise well-run organisations.
No. The institution retains accountability for technology risk regardless of the vendor's reputation or certifications — due diligence and ongoing oversight remain the institution's responsibility under MAS's Guidelines.
They're related but distinct — an internal gap assessment looks at your own systems and controls; vendor oversight looks at the risk a third party introduces on your behalf. A complete TRM posture needs both.
This should be disclosed and assessed as part of due diligence, not discovered later. Sub-outsourcing introduces an additional layer of risk the institution remains accountable for.
Book a free MAS TRM consultation and we'll help you think through the questions your outsourcing arrangement actually needs answered.