Global Standard Setters Take Aim at Cyber & Third-Party Risks in Financial Market Infrastructure
Key Takeaways
- New Cyber Toolkit: CPMI-IOSCO published a voluntary, non-binding toolkit designed to help financial market infrastructures strengthen their cyber resilience frameworks and implement operational resilience-related elements of the PFMI.
- Existing Guidance Remains: The toolkit complements, rather than replaces, CPMI-IOSCO’s 2016 cyber resilience guidance, adding practical considerations for FMIs applying the existing framework.
- Third-Party Reliance in Focus: A separate discussion paper examines challenges and risks arising from FMIs’ increased reliance on third-party service providers, particularly for critical services.
- Stakeholder Input Sought: CPMI-IOSCO are seeking feedback on the risks identified in the third-party discussion paper and on potential further engagement by the standard-setting bodies.
Deep Dive
The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) on Tuesday published two consultative documents aimed at financial market infrastructures, or FMIs, pairing a practical cyber resilience toolkit with a discussion paper examining the risks created by FMIs’ growing reliance on third-party service providers.
The two documents approach the problem from different directions. The cyber toolkit is intended to help FMIs strengthen their own defenses and operational resilience practices. The discussion paper turns outward, toward the vendors and other providers on which those infrastructures increasingly depend, particularly when critical services are involved.
Together, they reflect the difficulty of drawing a neat boundary around operational resilience when important systems, technologies and services may sit beyond an FMI’s direct control.
The cyber resilience toolkit provides voluntary, non-binding tools and practical considerations across several areas of cyber resilience. It is designed to support implementation of the operational resilience-related components of the CPMI-IOSCO Principles for Financial Market Infrastructures, the international standards governing payment systems, central securities depositories, securities settlement systems, central counterparties and trade repositories.
It does not replace CPMI-IOSCO’s existing cyber framework. Instead, the new toolkit is designed to complement the standard setters’ 2016 guidance on cyber resilience for FMIs, giving infrastructure operators a more practical set of tools for putting those expectations into effect.
That distinction matters. The toolkit is not a new binding standard, nor does its publication itself impose additional regulatory obligations. Its purpose is more practical: helping FMIs translate established resilience principles into the systems and practices used to withstand and recover from cyber disruption.
The accompanying discussion paper takes up a problem that can make that task considerably harder.
CPMI and IOSCO said FMIs have become increasingly reliant on third-party service providers, including for the delivery of critical services. The paper examines the challenges associated with that reliance and how they may amplify risks within organizations that occupy particularly interconnected positions in the financial system.
For an FMI, a problem at a provider can therefore be more than an ordinary vendor-management headache. The concern identified by the standard setters is rooted in the role these infrastructures play in payments, clearing and settlement: disruption affecting a service on which an FMI depends can intersect with the broader operational and financial-stability risks that the international framework is designed to contain.
The discussion paper stops short of prescribing a new approach. It instead poses questions to industry participants about the risks CPMI and IOSCO have identified and about what further engagement by the standard setters may be warranted. Its publication alongside the cyber toolkit also makes the relationship between the two subjects explicit: an FMI’s cyber resilience cannot be considered entirely apart from the external providers through which some of its services may be delivered.
That leaves third-party risk sitting squarely inside the resilience conversation. An FMI can strengthen its internal cyber framework, but its ability to maintain critical operations may still depend on organizations outside its walls. The discussion now underway is partly about how the existing expectations for resilience should contend with that reality without pretending that outsourced services amount to outsourced responsibility.
Both documents remain consultative. CPMI and IOSCO are seeking stakeholder comments on the cyber toolkit and the third-party services discussion paper through Dec. 1, 2026. Submissions are to be sent to both the BIS CPMI Secretariat and IOSCO Secretariat, and the organizations said comments will generally be published unless respondents request otherwise.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

