HomeBlogThird-Party Risk
Third-Party Risk

One Supplier Assurance Programme for APRA CPS 230, MAS, HKMA, SAMA and the CBUAE

Sep 2026 · 11 min read

Macro view of a watch movement with interlocking rose gold and titanium gears and ruby jewels, one central gear in sharp focus

The most disruptive incidents of the past two years were not attacks on banks. They were failures at suppliers: a faulty security update that stopped airlines and payment systems, stolen credentials at a cloud data platform, stolen tokens in a sales software integration, ransomware at an airport check-in provider. Verizon's [2026 Data Breach Investigations Report](https://www.verizon.com/about/news/breach-industry-wide-dbir-finds) found a third party involved in 48% of breaches, up from about 30% the year before. Regulators have responded by moving from outsourcing rules to third-party risk rules. For a financial group operating across Australia, Singapore, Hong Kong and the Gulf, that means several registers, several contract checklists and several approval processes for the same suppliers. This article shows where those rules overlap, where they differ, and how to run them as one programme.

From outsourcing to third-party risk

Older outsourcing rules asked whether a function had been handed to someone else. The new rules ask whether the institution relies on a provider for a critical operation, whatever the contract is called. Software as a service, cloud platforms, payment processors, data providers and AI model providers are all in scope.

RegulatorInstrumentStatus in September 2026Supplier register
APRA (Australia)CPS 230 Operational Risk ManagementIn force since 1 July 2025; legacy contracts compliant by 1 July 2026Material service provider register submitted annually
MAS (Singapore)Notice 658 and Outsourcing Guidelines; proposed Third-Party Risk Management GuidelinesTPRM Guidelines consulted on 6 March 2026, not yet finalProposed twice-yearly register of third-party arrangements
HKMA (Hong Kong)SPM OR-2 operational resilience; SA-2 outsourcingResilience required by 31 May 2026; HKMA reports all institutions achieved itMapping of critical operations to providers, reviewed at least annually
SAMA (Saudi Arabia)Rules on Outsourcing; SAMA Cyber Security Framework; NCA ECC domain 4In forceNo objection from SAMA before material outsourcing
CBUAE (UAE)Operational Risk Management Regulation, C 1/2026, Article 13; Outsourcing Regulation for BanksIn force from 14 September 2026Register of arrangements linked to critical operations
CBK (Kuwait)Cyber and Operational Resilience FrameworkIssued December 2025Third-party risk management is one of three baselines
QCB (Qatar)Cloud Computing Regulation, 2024In forceQCB approval before a cloud arrangement

What the rules have in common

Isometric illustration of a central supplier register hub with cards for cloud, payments, SaaS and AI providers, linked to several regulator buildings
One register of suppliers and critical operations can feed every regulator's return.
  1. A register tied to critical operations. APRA, the CBUAE and the proposed MAS guidelines all want a register that shows which providers support which critical operations.
  2. Due diligence before signing. Every regime expects risk assessment before entering into, or materially changing, an arrangement.
  3. Contract terms that give access. Audit and information rights for the institution and, in most regimes, for the regulator.
  4. Subcontractor visibility. CPS 230 requires notice when a provider relies on other material providers, and the CBUAE requires key terms to be enforceable against subcontractors handling the institution's data.
  5. Tested exit plans. Credible termination and substitution plans, not a paragraph in a policy.
  6. Concentration analysis. Regulators are using registers to find system-wide dependencies, and the CBUAE can order an institution to reduce excessive reliance on third parties.

Where the regimes differ

QuestionAustraliaSingaporeUAESaudi Arabia
Regulator approval before contracting?No; notify within 20 business days after entering a critical arrangement, and before material offshoringNot generally for outsourcing under the guidelinesNon-objection before outsourcing activities that could significantly affect critical operationsNo objection before material outsourcing
Regulator access in the contract?Standing APRA access clause in every material contractCooperation requested after an adverse developmentCBUAE onsite examination rights for arrangements affecting critical operationsRight to audit expected under the SAMA Cyber Security Framework
Data location?No general rule; offshoring needs prior noticeNo general ruleMaster system of record kept in the UAE at all timesData classification and hosting controls under NCA rules
Register frequency?AnnualTwice yearly (proposed)Maintained and availableMaintained and available

The differences decide the operating model. A supplier used across the group may need a standing Australian access clause, a UAE subcontractor clause and a Saudi approval, all at once. Negotiating the strictest terms once is far cheaper than renegotiating country by country.

The Australian notification timing is taken from the CPS 230 standard as summarised by APRA; confirm paragraph references against the current version before relying on them in contracts.

Lessons from the supplier failures of 2024 and 2025

IncidentWhat happenedControl lesson
CrowdStrike, July 2024A faulty update affected about 8.5 million Windows devices worldwideMap critical software vendors, not only hosting and outsourcing providers; test multi-vendor failure scenarios
Snowflake customer breaches, 2024Stolen credentials used against about 165 customer instances without MFAShared responsibility: the customer's configuration is part of supplier risk
Salesloft Drift, August 2025Stolen OAuth tokens used to export data from Salesforce instances at more than 700 organisationsInventory integrations and tokens as third-party connections
Collins Aerospace, September 2025Ransomware disrupted check-in and boarding systems at several European airportsA single niche provider can be a sector-wide dependency
Jaguar Land Rover, 2025The UK Cyber Monitoring Centre estimated about £1.9 billion of economic cost across more than 5,000 organisationsSupplier and customer impact belong in impact tolerances

APRA Member Suzanne Smith told an assurance forum in October 2025 that auditors should look for scenario tests in which several entities and several vendors fail at once. That is the standard to aim for.

Designing one programme

Isometric illustration of a supplier lifecycle loop with stations for onboarding, due diligence, contract, monitoring and exit, around a concentration risk gauge
Onboard, assess, contract, monitor, exit: one lifecycle with one set of evidence.
  • One register, many views. Hold suppliers, services, critical operations, locations, subcontractors and contract terms once, and generate each regulator's return from it.
  • One contract baseline. A group schedule with the union of required terms: audit and regulator access, subcontractor notice and flow-down, incident notification, data location, and termination assistance.
  • Tiering by criticality. Deep assurance for providers supporting critical operations; lighter checks elsewhere.
  • Continuous monitoring. Security ratings, assurance reports, incident notices and contract milestones tracked between annual reviews.
  • Exit plans that are tested. At least one tabletop exercise a year for the most critical providers, with evidence of the results.
  • Concentration reporting. A board view of reliance on the largest cloud and technology providers, including fourth parties such as the foundation models behind AI services.

For region-specific depth, see our guides to third-party and cloud risk in the GCC, BNM RMiT third-party and cloud risk and CPS 230 versus CPS 234.

Supplier assurance in GRCLens

GRCLens keeps suppliers, services, critical operations and contracts in one register linked to risks and controls. Supplier assessments are sent and scored in the platform, evidence is attached with its date, and each supplier maps to CPS 230, MAS, HKMA, SAMA, CBUAE, CBK and QCB requirements at once. Concentration and criticality views are available for the board, and the whole platform can run inside your own infrastructure where data residency rules apply.

Frequently asked questions

What is a material service provider under CPS 230?

A provider an APRA-regulated entity relies on for a critical operation, or one that exposes it to material operational risk. Some categories, such as core technology and internal audit, are treated as material unless the entity justifies otherwise.

Are the MAS Third-Party Risk Management Guidelines final?

Not as of late September 2026. MAS consulted from 6 March to 20 April 2026 and proposed that the guidelines take effect six months after they are issued.

What does CBUAE Circular 1/2026 require for third parties?

Article 13 of the Operational Risk Management Regulation requires a board-approved third-party risk strategy, due diligence, audit and CBUAE access rights, a register of arrangements linked to critical operations, and viable exit plans. It took effect on 14 September 2026.

How often should supplier exit plans be tested?

No regulator above fixes a frequency, but testing the most critical providers at least once a year, and recording the results, is a reasonable baseline.

How Security Solution Consultants can help

Security Solution Consultants designs supplier registers, contract baselines and exit testing programmes for financial institutions that answer to APRA, MAS, HKMA and Gulf regulators. See our compliance and risk management advisory, our security compliance services and our guide to CPS 230 compliance after transition. GRCLens then keeps the register, assessments and evidence current. Request a demonstration.

This article is general information, not legal advice. Regulations change, so confirm current requirements with the relevant regulator before relying on them. Questions?info@grclens.net.

← All articles