Third-party service risk management requires proportionate due diligence, binding information-sharing arrangements, and continuous monitoring of critical services. Payment Service Providers must conduct proportionate planning and due diligence before engaging Third-party Service Providers for critical services. The ... Summary
Third-party service risk management requires proportionate due diligence, binding information-sharing arrangements, and continuous monitoring of critical services.
Payment Service Providers must conduct proportionate planning and due diligence before engaging Third-party Service Providers for critical services. The assessment covers operational capability, financial soundness, risk controls, ICT and cyber-security risks, supply-chain dependencies, conflicts, regulatory-compliance capability and substitutability. Critical services require legally binding arrangements, including information-sharing obligations with the Authority, and ongoing monitoring of the provider's contractual performance.
Full Summary is available for active users!
Note: It is a system-generated summary and is for quick reference only.