In a recent Huffington Post article, Shared Assessments senior director Tom Garrubba discussed how third-party risk management has become an important topic to many executives and board members around the world. He recalls a conversation he had with Robin Jones, a member of the U.K.’s Financial Conduct Authority (FCA), during a conference in London. Jones expressed that his “unit [has been] paying renewed focus on technology resiliency and outsourcing.”
Technology resiliency and outsourcing, or “TRO,” appears in the Federal Financial Institutions Examination Council’s (FFIEC) “Business Continuity Planning” booklet. (The FFIEC is a U.S.-based banking regulatory body.) The booklet—which is a part of the FFIEC’s IT Examination Handbook—“provides guidance to assist examiners in evaluating financial institution and service provider risk management processes to ensure the availability of critical financial services.” Specifically, the idea of both technology resiliency and technology outsourcing are mentioned in the section titled “Appendix J: Strengthening the Resilience of Outsourced Technology Services.”
Looking to streamline your vendor risk management process? Take a look at these tools and techniques.
As you can see, TRO has become widely discussed both in U.S. and international regulatory spaces. And in the last 10 years, many regulators have also begun examining how critical third parties could affect the cybersecurity posture of a financial institution through their network access. Below, we’ll walk through what this appendix discusses in regard to TRO and how you can apply those best practices in your organization.