CPMI-IOSCO Third-Party Risk at FMIs: The 1 December Deadline

On 8 September 2026 the Committee on Payments and Market Infrastructures and the International Organization of Securities Commissions published for public comment a discussion paper, “FMIs’ reliance on third-party service providers: challenges and risks,” and set a comment deadline of 1 December 2026. It is the clearest signal yet of where CPMI-IOSCO third-party risk work for financial market infrastructures is heading, and it lands as payment systems, central securities depositories, securities settlement systems, central counterparties and trade repositories push more of their critical services onto outside providers. It maps six categories of challenge and asks whether the map is complete, adding no new template, return, or standard.

The anchor decides how much weight to give it. CPMI-IOSCO built the paper on the 2012 Principles for financial market infrastructures, specifically Principle 17 on operational risk and Annex F on oversight expectations for critical service providers. The cover note states that the paper “is not intended to impose additional standards beyond those set out in the PFMI.” The discussion paper does not itself alter the PFMI; legally binding obligations continue to depend on the applicable jurisdictional framework. What has changed is the picture CPMI-IOSCO now holds of where those duties are hardest to meet, assembled from surveys of member authorities and FMIs, two industry roundtables, and the committees’ own Level 3 implementation reviews.

For a reporting or resilience team inside an FMI, the operative question is narrow. Which of the six challenges already describes your operating model, and is a written response worth filing before the window closes.

Related reading: the companion CPMI-IOSCO cyber resilience toolkit for FMIs, published for consultation on the same day.

What the CPMI-IOSCO third-party risk paper is, and what it is not

The paper carries consultative status. CPMI-IOSCO confirm in both the cover note and the executive summary that it adds no standards or guidance for FMIs beyond those already in the PFMI. The committees analysed the current state of FMIs’ reliance on third parties, grouped the risk-management difficulties they found into six categories, and set out questions to test whether industry recognises those categories and whether further work would help.

The dates and boundaries worth pinning to a wall:

  • Published for comment: 8 September 2026.
  • Status: discussion paper, consultative. No new obligation, no new reporting return.
  • Comment deadline: 1 December 2026, by email to the CPMI and IOSCO secretariats.
  • Standards anchor: the 2012 PFMI, Principle 17 (operational risk) and Annex F (Oversight expectations applicable to critical service providers), as adopted or applied by the relevant authorities.
  • Companion consultation, same day: the cyber resilience toolkit for FMIs, a set of voluntary, non-binding tools.

Scope is wider than shorthand suggests. For this paper an FMI means a payment system, a central securities depository, a securities settlement system, a central counterparty or a trade repository. The term “third-party service provider” is also drawn wide: CPMI-IOSCO fold intra-group arrangements into it, so a service delivered by an affiliate inside the same group counts as much as one bought from an external vendor. An FMI that treats group-provided IT as automatically lower risk has already parted company with the paper’s framing.

The six challenges the paper puts to industry

CPMI-IOSCO group the difficulties into six categories. Two concern ecosystem structure: increasing complexity and interconnectedness, and concentration of third-party service providers. Three concern the individual FMI-provider relationship: complex and opaque supply chains, difficulties with exit planning, and imbalances in bargaining power. The sixth is variation in regulatory, supervisory and oversight expectations across jurisdictions.

  1. Increasing complexity and interconnectedness of FMIs’ ecosystems, which widens both exposure to risk and the ability to transmit it, cyber risk included.
  2. Concentration of third-party service providers, at the level of the individual FMI and at the level of the wider ecosystem.
  3. Complex and opaque supply chains, which make critical dependencies hard to identify and resilience planning harder to complete.
  4. Difficulties with exit planning, where substitution or termination is impractical even when a substitute exists.
  5. Imbalances in bargaining power, which leave an FMI with limited room to negotiate the contractual terms its risk framework needs.
  6. Variation in regulatory, supervisory and oversight expectations across jurisdictions, which complicates a single consistent framework.

The reason CPMI-IOSCO treat these as an FMI-specific problem, even though they touch the whole financial sector, is concentration of function. An FMI centralises activity by design, so a disruption that would be contained inside one bank can cascade when it lands on the node that many banks share. That is the thread the survey questions keep returning to.

Concentration and the vendor lock-in problem

Concentration is the challenge the survey data speaks to most directly. Around three quarters of FMI respondents rated the risk from both market concentration, meaning few providers exist for a given service, and concentration by choice of provider, meaning a decision to route several services through one vendor, as either medium or high. The two are not felt evenly across the sector. Larger FMIs operating in two or more regions tend to weight market concentration more heavily; smaller FMIs in a single jurisdiction tend to worry more about concentration by choice, the road that leads to vendor lock-in.

The common misreading is that concentration risk lives in the market structure alone, something an FMI simply inherits from the market and cannot influence. The paper resists that. Where one provider supplies cloud hosting and data analytics and messaging, the depth of that relationship, not the number of vendors in the market, is what makes switching slow and costly. Interoperability gaps and bespoke architecture can leave an FMI unable to move once a contract ends or a provider underperforms, and least able to move in exactly the stressed moment when it most needs to. CPMI-IOSCO also note the counterweight raised at the roundtable: every new provider added to reduce concentration introduces its own third-party risk and its own administrative cost, so diversification is not free.

There is a second layer that no single FMI can see. When one provider serves many FMIs, its failure could disrupt several at once, potentially across borders, which is why some authorities now seek a system-wide view of which providers FMIs use. The paper is candid about the limit here: an FMI supervisor can usually only gather data within its own sector and its own jurisdiction, leaving the cross-system and global picture out of reach.

Supply chains that go dark past the fourth party

Visibility is where the paper turns most concrete, and where a widely held assumption breaks. Most FMIs told CPMI-IOSCO they can see their fourth-party providers, the providers behind their providers, but only a few can see past that. Roughly one-third said their visibility stopped at the direct third party. The point CPMI-IOSCO press is that seeing a dependency does not confer the data quality, the skill, or the contractual reach to control the risk it carries.

This is where Principle 17 does real work. Explanatory note 3.17.20 of the PFMI addresses this directly. It requires an FMI to ensure that outsourced operations meet the same requirements as if provided internally, and to have robust arrangements for the selection and substitution of providers, timely access to all necessary information, and the proper controls and monitoring tools. The same note also states that a contractual relationship should be in place allowing the FMI and relevant authorities to have full access to necessary information, and that the FMI’s approval is mandatory before the critical service provider can itself outsource material elements of the service. Providers, for their part, said they monitor their own critical suppliers and pass on the impact of any fourth-party incident, but that visibility degrades quickly further down the chain. The Basel Committee’s principles for the sound management of third-party risk, which is a banking-sector standard, state that critical third-party contracts should address key nth parties and include rights for banks to access, audit and obtain relevant information from those key nth parties. For an FMI, the practical follow-through is to test whether the sub-outsourcing-approval clause in each critical contract is actually exercised, not merely present.

Exit plans that read well, and bargaining power that does not

Around two-thirds of FMIs told CPMI-IOSCO they use exit planning to preserve their ability to substitute a provider, building termination rights into contracts for both business-as-usual and crisis conditions. The honest finding is how far the paper is from treating an exit plan as a solved control. Providers at their own roundtable were sceptical of lengthy exit plans, arguing that such documents can prove impractical in a real incident and that fully exiting a relationship is unrealistic given the range of services involved. Exit planning is a mitigant, and its effectiveness depends on the criticality of the service and whether a genuine alternative can absorb the migration under stress.

Bargaining power sits underneath the exit problem. Certain FMIs reported having limited to no negotiating room and receiving pre-set contracts they could take or leave, a direct consequence of provider concentration and of the FMI’s relative size as a customer. From the other side of the table, providers said they try to standardise contracts across jurisdictions, and some maintain a “financial services addendum,” rolling a negotiated change out widely across clients. The result is a market where the terms an FMI’s risk framework requires may simply not be on offer, which is one reason the paper asks respondents to name the contractual aspects they find hardest to secure. A pre-set contract that omits an enforceable audit right or a workable exit trigger is a gap the FMI has to manage by other means, and to document as such.

Where Principle 17 and Annex F still set the bar

Because the paper changes no rule, the standard that governs an FMI’s third parties is the one already in force. Principle 17 states that “an FMI should identify, monitor, and manage the risks that key participants, other FMIs, and service and utility providers might pose to its operations,” and that it should also manage the risks its operations might pose to other FMIs. Across jurisdictions, CPMI-IOSCO found, relevant regulations tend to draw on Principle 17 and Annex F, and authorities generally hold that the FMI retains ultimate responsibility for risks arising from activities it has handed to a provider. Outsourcing the service does not outsource the accountability.

For EU FMIs that are themselves financial entities within DORA’s Article 2 scope, a binding ICT-resilience regime already occupies much of this ground. DORA expressly covers central securities depositories, central counterparties and trade repositories, but it does not list payment systems or securities settlement systems as FMI categories in their own right. The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied since 17 January 2025 and treats central counterparties, central securities depositories and trade repositories as financial entities, with obligations on ICT risk management, a register of information covering ICT third-party contractual arrangements, and a Union oversight framework for critical ICT third-party providers designated under Article 31. The CPMI-IOSCO paper sits above that binding framework as global diagnosis. An EU FMI that is itself within DORA’s Article 2 scope can compare the paper’s third-party-risk themes with its existing DORA ICT third-party-risk framework, alongside the mechanics of DORA ICT incident reporting. FMIs that clear or record derivatives will also see the overlap with their existing EMIR reporting obligations, which sit on the same operational base.

Jurisdictional variation is a gap the paper cannot close alone

The sixth challenge is the one CPMI-IOSCO are least able to resolve, and they say so. Requirements differ across jurisdictions in how specific they are: some authorities set out detailed expectations on due diligence, contractual clauses, access rights and business continuity testing, while others state general principles. Data collection differs too. Most authorities gather information on direct providers; only some reach nth-party subcontractors along the supply chain. A cross-border provider therefore faces a patchwork, and an FMI operating in several jurisdictions faces the same patchwork from the other direction. As a concrete instance of the detailed end of the spectrum, the Bank of England issued a supervisory statement in February 2023 on outsourcing and third-party risk management for recognised payment system operators and specified service providers, one national framework whose requirements and expectations apply to the in-scope recognised payment system operators and specified service providers and therefore shape the contractual requirements they place on third parties.

One structural wrinkle the paper records is that FMIs are themselves treated as third-party service providers by other financial-sector firms, so an FMI can carry the regulatory burden of both a regulated entity and a provider. Variation of this kind is partly unavoidable, rooted in national frameworks, mandates and legal powers, which is why CPMI-IOSCO frame harmonisation as an open question for feedback, one they cannot promise to deliver.

What the consultation asks, and how to respond

Section 4 of the paper sets out eleven questions in three groups. Five are for all stakeholders: whether the six challenges are accurate and complete, what solutions exist for each, whether further CPMI-IOSCO engagement or policy would help, whether broader discussion would be useful, and which contractual aspects are most difficult. Two are addressed to FMIs, on which international publications they use to design their frameworks and which emerging cross-jurisdictional topics authorities should know about. The final four go to third-party providers, on their insight into how critical their services are to FMIs, the information and contractual rights they offer, any conflicts between the rules they follow and those their FMI clients follow, and their own read on emerging cross-border issues.

Responses go by email to both secretariats, cpmi@bis.org and cpmi-iosco@iosco.org, by 1 December 2026. CPMI-IOSCO will publish responses on the BIS and IOSCO websites unless a respondent expressly asks otherwise, and they warn against including commercial, personal or other sensitive information, or flagging redactions clearly where it cannot be avoided. A firm that has lived one of the six challenges, an unenforceable audit right, a stalled exit, a supply chain that goes dark past the fourth party, holds exactly the evidence the questions are fishing for. The decision to file, and what to redact, is worth settling in good time, well before the last week of November.

Frequently Asked Questions

Does the discussion paper create a new reporting obligation or supervisory expectation for FMIs?

The paper carries consultative status only; CPMI-IOSCO confirm it adds no standards beyond the PFMI and creates no new guidance. Any binding requirements remain those imposed through the applicable jurisdictional implementation of the PFMI and other local rules; Principle 17 and Annex F are international standards and oversight expectations. The paper signals where future policy work might go, which is a reason to read it, but it changes no return, deadline or template today.

Which entities count as an FMI for this paper?

Payment systems, central securities depositories, securities settlement systems, central counterparties and trade repositories. That is broader than the “CCPs, CSDs and payment systems” shorthand, so a securities settlement system or a trade repository that assumed it was out of scope should read itself back in.

Are intra-group arrangements inside the scope, or only external vendors?

Both. The paper widens the usual definition to include intra-group arrangements, and the surveyed FMIs said they hold group entities to the same standards as external providers. An affiliate supplying critical IT is a third-party service provider for these purposes.

How does this interact with DORA for an EU FMI?

For FMIs that are financial entities within DORA’s Article 2 scope, Regulation (EU) 2022/2554 has applied since 17 January 2025 and includes the register of information on ICT third-party contractual arrangements and the Article 31 framework for designation of critical ICT third-party service providers. The CPMI-IOSCO paper is a non-binding global diagnosis that overlaps heavily with DORA’s third-party provisions but amends none of them. Reconciling the two is a mapping exercise; it does not require a second compliance programme.

Is the cyber resilience toolkit part of the same consultation?

It is a separate but linked consultative publication released the same day, comprising voluntary, non-binding tools across four topics and informed by the 2016 CPMI-IOSCO cyber guidance. It considers cyber resilience partly through the lens of third-party risk, so the two documents are best read together even though each stands on its own.

If we respond, can our submission stay confidential?

Responses are published on the BIS and IOSCO websites by default. A respondent can expressly request otherwise, and the committees ask that sensitive or commercial information be left out or clearly marked for redaction. Decide the confidentiality position before drafting, because it shapes how much operational detail a submission can safely carry.

Why does the paper single out visibility past the fourth party?

Because that is where the survey shows the drop-off. Most FMIs can see fourth parties; few see beyond, and roughly a third see only their direct provider. PFMI Principle 17 requires an FMI to identify and manage risks arising from service and utility providers, including indirect effects from external operational failures.

Key Takeaways

  • Comment deadline is 1 December 2026, by email to cpmi@bis.org and cpmi-iosco@iosco.org; decide confidentiality and redactions before drafting, as responses are published by default.
  • The paper is consultative and adds no standard: it is anchored in PFMI Principle 17 and Annex F as international standards and oversight expectations, and the FMI retains ultimate responsibility for outsourced activities.
  • Scope includes payment systems, CSDs, securities settlement systems, CCPs and trade repositories, and treats intra-group arrangements as third-party service providers.
  • Around three quarters of FMIs rate both market concentration and concentration-by-choice as medium or high risk; larger multi-region firms weight the former, smaller single-jurisdiction firms the latter.
  • Most FMIs see only to the fourth party and roughly one-third only to the direct provider; test whether each critical contract’s sub-outsourcing-approval and audit rights are actually exercised.
  • Around two-thirds use exit planning, yet providers doubt lengthy exit plans work under stress; document where a pre-set contract omits an enforceable exit or audit term.
  • EU FMIs that are within DORA’s Article 2 scope should map the paper’s third-party-risk themes against their existing DORA framework; other EU FMIs should first establish whether their operator is independently a DORA financial entity.

Sources and References

Reading the discussion paper as an early signal

Nothing in this paper obliges an FMI to change a control tomorrow. What it does is tell FMIs, their participants and their critical providers which parts of the third-party problem CPMI-IOSCO believe are least settled, and invite them to say whether that reading is right. The six challenges are a shortlist of where future policy or supervisory attention could concentrate, and concentration, supply-chain opacity and exit planning are the three that the survey evidence pushes hardest. The concrete task before 1 December 2026 is to decide whether to file a response, and either way to pull the current concentration and supply-chain map off the shelf and test it against the six categories while the questions are still open.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • CSSF IFM Ancillary Services Notification: What Luxembourg Fund Managers Must File Before Going Live

    Updated July 2026In this guideWhat the CSSF IFM ancillary services notification actually requiresWhere the legal certainty comes from: AIFMD II Article 6The MiFID II overlay teams underestimateUpdating the articles of incorporation is not a rubber stampWhen this applies and what the CSSF did not sayFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesFiling the notification before the…

  • FSB AI Sound Practices: Consultation Closes, Final Report Next

    On 6 August 2026 the Financial Stability Board published the public responses to its consultation on Sound Practices for Responsible Adoption of Artificial Intelligence (AI). The FSB AI sound practices were put out for comment on 10 June 2026, the comment window closed on 22 July 2026, and the FSB now says it expects to…

  • UK Money Market Fund Reform: What FCA Managers Must Watch

    Updated July 2026In this guideWhat the UK Money Market Fund reform changesThe onshored rules the reform sits onFrom a 50 percent floor to a 40 percent expectationDelinking: cutting the automatic tie to fees and gatesKnow your customer and investor concentrationWhen the new rules landFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesSizing your weekly liquid asset buffers…

  • FASTER Directive Market Capitalisation Data: Securities Scope

    On 10 July 2026, the European Securities and Markets Authority published the first set of market capitalisation figures and ratios for EU Member States under the FASTER Directive, Council Directive (EU) 2025/50. The figures cover reference years 2024 and 2025, and they start a multi-year clock that will decide which national markets have to build…

  • ESRS-40a for Non-EU Undertakings: The FY2028 Reporting Trigger

    On 11 September 2026 EFRAG opened a survey asking large non-EU companies to put a number on the cost of a reporting obligation many of them have not yet started to build for. The obligation sits in Articles 40a to 40d of the EU Accounting Directive: from financial year 2028, the EU subsidiary or branch…