The Financial Supervisory Service said on the 29th it has prepared the "third-party IT risk management guidelines for financial companies" to systematically manage risks stemming from the expanded use of external IT services by financial firms, such as cloud and software as a service (SaaS).
The guidelines clarify the roles and responsibilities of the board of directors and management. They state that the board bears ultimate responsibility for third-party IT risk management and define key items related to risk management policy and oversight as matters for review and resolution. They also designate management as the party responsible for establishing, implementing, and maintaining the third-party IT risk management framework, and require the designation and operation of a central management department. The central management department will formulate and execute effective safety measures, oversee each business unit's status of delegated information processing tasks, and evaluate the status of third-party IT risks and the appropriateness of outsourcing contracts.
Based on this, financial companies are to build and operate a "three lines of control" composed of a central management department, a risk management department, and an internal audit department to systematically manage third-party IT risks.
The system for identifying, assessing, and managing third-party IT risks is also specified. Financial firms must identify key business-related information on the third party that is the counterparty to the outsourcing contract—such as financial soundness, services provided, types and volumes of processed information, encryption and communication methods, incident response systems, and IT facilities—and conduct periodic inspections at least once every half-year to keep related information up to date. In particular, any "key third party" that has a significant impact on a financial firm's operations or on financial consumers is to be designated separately and subject to stronger risk management.
In addition, specific evaluation items and checklists are presented so that IT risks can be effectively assessed for each third party. For identified risks, remedial measures are to be taken; if control, mitigation, or transfer is not possible, the contract must be suspended or the board must decide whether to maintain the contract.
Risk management procedures by contract stage are also systematized. From the contract review and conclusion stage through maintenance and management to termination, stage-by-stage procedures have been established to proactively identify and respond to potential third-party IT risks that may arise throughout the entire outsourcing process for information processing tasks.
Before concluding a contract, service capabilities and information security management systems are to be verified through on-site due diligence and other means, and essential items—such as division of roles between the principal and the contractor and allocation of responsibility in the event of an incident—are to be reflected in the contract. During the contract period, the status of contract performance must be inspected regularly at least once a year, and contingency plans for system outages, a backup management system to ensure business continuity, and an exit strategy for contract termination must be prepared. After contract termination, the return of information assets, revocation of access rights, and complete destruction of information must be carried out.
The Financial Supervisory Service (FSS) and industry associations by sector plan to actively support the effective operation of the newly prepared "third-party IT risk management guidelines." Industry associations by sector will establish best practice standards based on these guidelines and implement them from November this year.