
The most disruptive incidents of the past two years were not attacks on banks. They were failures at suppliers: a faulty security update that stopped airlines and payment systems, stolen credentials at a cloud data platform, stolen tokens in a sales software integration, ransomware at an airport check-in provider. Verizon's [2026 Data Breach Investigations Report](https://www.verizon.com/about/news/breach-industry-wide-dbir-finds) found a third party involved in 48% of breaches, up from about 30% the year before. Regulators have responded by moving from outsourcing rules to third-party risk rules. For a financial group operating across Australia, Singapore, Hong Kong and the Gulf, that means several registers, several contract checklists and several approval processes for the same suppliers. This article shows where those rules overlap, where they differ, and how to run them as one programme.
From outsourcing to third-party risk
Older outsourcing rules asked whether a function had been handed to someone else. The new rules ask whether the institution relies on a provider for a critical operation, whatever the contract is called. Software as a service, cloud platforms, payment processors, data providers and AI model providers are all in scope.
| Regulator | Instrument | Status in September 2026 | Supplier register |
|---|---|---|---|
| APRA (Australia) | CPS 230 Operational Risk Management | In force since 1 July 2025; legacy contracts compliant by 1 July 2026 | Material service provider register submitted annually |
| MAS (Singapore) | Notice 658 and Outsourcing Guidelines; proposed Third-Party Risk Management Guidelines | TPRM Guidelines consulted on 6 March 2026, not yet final | Proposed twice-yearly register of third-party arrangements |
| HKMA (Hong Kong) | SPM OR-2 operational resilience; SA-2 outsourcing | Resilience required by 31 May 2026; HKMA reports all institutions achieved it | Mapping of critical operations to providers, reviewed at least annually |
| SAMA (Saudi Arabia) | Rules on Outsourcing; SAMA Cyber Security Framework; NCA ECC domain 4 | In force | No objection from SAMA before material outsourcing |
| CBUAE (UAE) | Operational Risk Management Regulation, C 1/2026, Article 13; Outsourcing Regulation for Banks | In force from 14 September 2026 | Register of arrangements linked to critical operations |
| CBK (Kuwait) | Cyber and Operational Resilience Framework | Issued December 2025 | Third-party risk management is one of three baselines |
| QCB (Qatar) | Cloud Computing Regulation, 2024 | In force | QCB approval before a cloud arrangement |
What the rules have in common

- A register tied to critical operations. APRA, the CBUAE and the proposed MAS guidelines all want a register that shows which providers support which critical operations.
- Due diligence before signing. Every regime expects risk assessment before entering into, or materially changing, an arrangement.
- Contract terms that give access. Audit and information rights for the institution and, in most regimes, for the regulator.
- Subcontractor visibility. CPS 230 requires notice when a provider relies on other material providers, and the CBUAE requires key terms to be enforceable against subcontractors handling the institution's data.
- Tested exit plans. Credible termination and substitution plans, not a paragraph in a policy.
- Concentration analysis. Regulators are using registers to find system-wide dependencies, and the CBUAE can order an institution to reduce excessive reliance on third parties.
Where the regimes differ
| Question | Australia | Singapore | UAE | Saudi Arabia |
|---|---|---|---|---|
| Regulator approval before contracting? | No; notify within 20 business days after entering a critical arrangement, and before material offshoring | Not generally for outsourcing under the guidelines | Non-objection before outsourcing activities that could significantly affect critical operations | No objection before material outsourcing |
| Regulator access in the contract? | Standing APRA access clause in every material contract | Cooperation requested after an adverse development | CBUAE onsite examination rights for arrangements affecting critical operations | Right to audit expected under the SAMA Cyber Security Framework |
| Data location? | No general rule; offshoring needs prior notice | No general rule | Master system of record kept in the UAE at all times | Data classification and hosting controls under NCA rules |
| Register frequency? | Annual | Twice yearly (proposed) | Maintained and available | Maintained and available |
The differences decide the operating model. A supplier used across the group may need a standing Australian access clause, a UAE subcontractor clause and a Saudi approval, all at once. Negotiating the strictest terms once is far cheaper than renegotiating country by country.
The Australian notification timing is taken from the CPS 230 standard as summarised by APRA; confirm paragraph references against the current version before relying on them in contracts.
Lessons from the supplier failures of 2024 and 2025
| Incident | What happened | Control lesson |
|---|---|---|
| CrowdStrike, July 2024 | A faulty update affected about 8.5 million Windows devices worldwide | Map critical software vendors, not only hosting and outsourcing providers; test multi-vendor failure scenarios |
| Snowflake customer breaches, 2024 | Stolen credentials used against about 165 customer instances without MFA | Shared responsibility: the customer's configuration is part of supplier risk |
| Salesloft Drift, August 2025 | Stolen OAuth tokens used to export data from Salesforce instances at more than 700 organisations | Inventory integrations and tokens as third-party connections |
| Collins Aerospace, September 2025 | Ransomware disrupted check-in and boarding systems at several European airports | A single niche provider can be a sector-wide dependency |
| Jaguar Land Rover, 2025 | The UK Cyber Monitoring Centre estimated about £1.9 billion of economic cost across more than 5,000 organisations | Supplier and customer impact belong in impact tolerances |
APRA Member Suzanne Smith told an assurance forum in October 2025 that auditors should look for scenario tests in which several entities and several vendors fail at once. That is the standard to aim for.
Designing one programme

- One register, many views. Hold suppliers, services, critical operations, locations, subcontractors and contract terms once, and generate each regulator's return from it.
- One contract baseline. A group schedule with the union of required terms: audit and regulator access, subcontractor notice and flow-down, incident notification, data location, and termination assistance.
- Tiering by criticality. Deep assurance for providers supporting critical operations; lighter checks elsewhere.
- Continuous monitoring. Security ratings, assurance reports, incident notices and contract milestones tracked between annual reviews.
- Exit plans that are tested. At least one tabletop exercise a year for the most critical providers, with evidence of the results.
- Concentration reporting. A board view of reliance on the largest cloud and technology providers, including fourth parties such as the foundation models behind AI services.
For region-specific depth, see our guides to third-party and cloud risk in the GCC, BNM RMiT third-party and cloud risk and CPS 230 versus CPS 234.
Supplier assurance in GRCLens
GRCLens keeps suppliers, services, critical operations and contracts in one register linked to risks and controls. Supplier assessments are sent and scored in the platform, evidence is attached with its date, and each supplier maps to CPS 230, MAS, HKMA, SAMA, CBUAE, CBK and QCB requirements at once. Concentration and criticality views are available for the board, and the whole platform can run inside your own infrastructure where data residency rules apply.
Frequently asked questions
What is a material service provider under CPS 230?
A provider an APRA-regulated entity relies on for a critical operation, or one that exposes it to material operational risk. Some categories, such as core technology and internal audit, are treated as material unless the entity justifies otherwise.
Are the MAS Third-Party Risk Management Guidelines final?
Not as of late September 2026. MAS consulted from 6 March to 20 April 2026 and proposed that the guidelines take effect six months after they are issued.
What does CBUAE Circular 1/2026 require for third parties?
Article 13 of the Operational Risk Management Regulation requires a board-approved third-party risk strategy, due diligence, audit and CBUAE access rights, a register of arrangements linked to critical operations, and viable exit plans. It took effect on 14 September 2026.
How often should supplier exit plans be tested?
No regulator above fixes a frequency, but testing the most critical providers at least once a year, and recording the results, is a reasonable baseline.
How Security Solution Consultants can help
Security Solution Consultants designs supplier registers, contract baselines and exit testing programmes for financial institutions that answer to APRA, MAS, HKMA and Gulf regulators. See our compliance and risk management advisory, our security compliance services and our guide to CPS 230 compliance after transition. GRCLens then keeps the register, assessments and evidence current. Request a demonstration.
Keep reading

RMiT 2025 for Malaysian financial institutions: the 90-day clock, cloud, and the supplier you forgot
Bank Negara Malaysia's revised Risk Management in Technology took effect on 28 November 2025. What changed, why external-party assurance and cloud consultation are where most gaps sit, and how to keep the annual self-assessment honest.

Third-party and cloud risk under GCC frameworks
Regulators in KSA and the UAE increasingly hold organizations accountable for their suppliers and cloud providers. Here's how to get ahead of it.

Autonomous Fleets Meet Critical Infrastructure Law: SOCI, New Zealand and the Gulf
Once an autonomous fleet moves freight or carries the public at scale, its operator starts to look like a critical infrastructure operator. What the SOCI Act, New Zealand's proposed regime and the Gulf rules ask for, and how to evidence it.