Banks use outside providers for cloud infrastructure, software, data, payments and customer services. These relationships can add capability and efficiency, but the bank remains responsible for understanding and managing the risks created by the service.

01

The risk starts with the service, not the vendor’s name

A bank first identifies what the provider will do, which data and systems it can access, and what would happen if the service became unavailable or performed incorrectly. A provider supporting a critical payment or account function requires greater scrutiny than one supplying a low-impact administrative tool.

This risk-based approach helps the institution apply effort in proportion to the importance and complexity of the relationship.

02

Due diligence tests capability and control

Before entering a material relationship, the bank may evaluate the provider’s financial condition, security, resilience, legal obligations, staffing, data practices, subcontractors and record of performance.

Due diligence cannot eliminate risk or guarantee future performance. It gives decision-makers evidence to decide whether the service, contract and remaining exposure are acceptable.

03

The contract creates enforceable expectations

A well-designed agreement addresses service levels, security, incident notification, audit and access rights, data ownership, regulatory cooperation, subcontracting, business continuity and termination.

The contract should reflect the actual operating arrangement. Standard terms that do not provide needed information, testing rights or exit support can weaken the bank’s ability to manage a critical dependency.

04

Monitoring continues after launch

The bank tracks performance, control reports, incidents, financial condition and material changes throughout the relationship. It also considers concentration risk when several important services depend on the same provider or technology.

Supply chains matter too. A provider may rely on subcontractors that the bank cannot see directly, creating dependencies beyond the immediate contract.

05

Exit planning must work under stress

For a critical service, the bank needs a realistic plan for disruption, termination or provider failure. That may involve recovering data, moving workloads, operating a temporary workaround or transferring the service to another provider.

An alternative listed on paper may not be usable quickly. Testing, technical compatibility, migration time and limited supplier choice determine whether the exit plan is practical.

Sources

Read the primary material

Banking Explained prioritizes regulators, official publications and first-party announcements.