EBA Narrows Third-Party Risk Rules to Critical Functions

The European Banking Authority (EBA) is moving towards a more targeted approach to third-party risk management, with regulatory attention increasingly focused on outsourcing arrangements involving critical or important functions. The approach is intended to reduce unnecessary compliance burdens while ensuring Read More …

TPAs’ Real Value Lies in Risk Management

Third-party administrators (TPAs) are increasingly being viewed not simply as service providers that help institutional investors and insurers select or administer portfolios, but as potential partners in risk management. The central argument is that the value of TPA relationships should Read More …

RBI Says Govern AI Before Scaling It

Reserve Bank of India (RBI) Deputy Governor Rohit Jain has outlined a 10-point framework for managing technology and cyber risks, urging banks to strengthen governance as artificial intelligence becomes increasingly embedded in financial services. Speaking at the State Bank of Read More …

RBI Sets 10 Technology and Cyber Risk Requirements

The Reserve Bank of India has outlined 10 key requirements covering technology and cyber-risk management for regulated entities, emphasising stronger governance, controls and resilience as financial institutions become increasingly dependent on digital infrastructure. The requirements focus on ensuring that technology Read More …

US Banks Face New Vendor Risk Guidance

Four US financial regulators have proposed new third-party risk management guidance aimed at helping banks and credit unions tailor vendor oversight to the actual risks posed by individual third-party relationships. The proposal was issued by the Office of the Comptroller Read More …

Security Risk Management Extends Beyond Illegal Mining

Security risk management in the mining sector is evolving beyond the traditional focus on illegal mining, encompassing a broader spectrum of operational, environmental, and strategic risks. The article highlights the need for a more comprehensive and integrated approach to managing Read More …

Banks Face New Third-Party Risk Rules

US federal banking regulators have proposed revised guidance for third-party risk management, seeking to replace existing guidance with a more risk-based framework for banks and credit unions. The proposal was issued jointly by the Office of the Comptroller of the Read More …

GenAI Reshapes Risk and Compliance

Generative artificial intelligence (GenAI) and large language models are increasingly being integrated into banking risk management and compliance, with potential applications spanning anti-money laundering, fraud prevention, customer due diligence, third-party risk, regulatory compliance and operational resilience. One of the clearest Read More …

Salesforce Outage Exposes Cloud Risk

A major Salesforce outage lasting about seven and a half hours on September 16 has highlighted the hidden resilience risks created by dependence on cloud-based platforms. The disruption affected multiple Salesforce instances across regions, causing severe delays, intermittent errors and Read More …

DORA Tightens Vendor Risk Rules

The European Union’s Digital Operational Resilience Act (DORA) is making third-party and ICT vendor risk management a formal regulatory responsibility for financial institutions, increasing the importance of documented controls, contractual safeguards and continuous oversight. DORA strengthens requirements around how financial Read More …