MAS third-party risk management guidelines

MAS Third-Party Risk Management: What Singapore Financial Institutions Must Fix Before the Guidelines Take Effect

On 6 March 2026, the Monetary Authority of Singapore (MAS) issued a consultation paper on proposed Guidelines on Third-Party Risk Management (TPRM). The consultation closed on 20 April 2026, and MAS proposed a six-month transition period following publication of the final guidelines.

The proposal would extend the existing outsourcing framework to third-party arrangements more broadly. The practical challenge is not only a policy update. It is bringing together information on providers, services, risk assessments, contracts, subcontractors, controls and continuity plans that may currently sit across different systems.

What the Proposed MAS Framework Changes

The proposed TPRM Guidelines would supersede MAS’s existing Guidelines on Outsourcing and apply more broadly to financial institutions that rely on third-party services. For banks and merchant banks, MAS Notices 658 and 1121 would remain in force.

The proposed framework covers four main areas: maintaining a register of third-party arrangements, governance and risk management, the third-party arrangement lifecycle from pre-contract assessment through termination, and subcontractor management.

Implementation is intended to be proportionate to the size and complexity of the financial institution and the nature and materiality of the third-party service.

MAS TPRM Guidelines, Status as of September 2026

Item Current Status
Consultation published 6 March 2026
Consultation closed 20 April 2026
Final guidelines Pending
Proposed implementation period Six months from issuance of the final guidelines
Proposed register reporting Semi-annual and upon MAS request
Current position Existing outsourcing requirements remain relevant pending the final framework

Why the Third-Party Register Matters

The proposed framework would require financial institutions to maintain a record of third-party arrangements and submit a register to MAS semi-annually and upon request. The submitted register would minimally cover material third-party arrangements, including material subcontractors where possible.

That makes data quality important. A useful register needs information such as the legal entity, service description, business function, materiality assessment, responsible owners, relevant contractual provisions, due diligence records and monitoring information.

The issue is not simply maintaining a larger list. It is maintaining a defensible record with supporting evidence.

Institutions may currently hold this information in procurement systems, contract repositories, email, incident systems and spreadsheets. Reconciliation then becomes a manual exercise.

From Outsourcing to Third-Party Services

The wider scope means institutions need to consider third-party arrangements beyond traditional outsourcing. Cloud tooling bought by marketing, a data vendor procured by a trading desk, a KYC screening API, or a managed print service with access to customer correspondence can illustrate the types of arrangements that may need assessment, depending on the nature and materiality of the service.

The proposed framework does not mean every provider receives the same level of scrutiny. The extent of risk management should reflect the institution’s size and complexity and the nature and materiality of the service.

Five Operational Stages

The proposed lifecycle can be viewed through five practical stages:

1. Risk assessment, before engagement and periodically thereafter.
2. Due diligence, including enhanced checks for material arrangements.
3. Contracting, including relevant provisions on audit rights, termination, business continuity and data location.
4. Monitoring, including ongoing oversight and independent audit where appropriate for material arrangements.
5. Termination, including documented exit arrangements for material services.

Each stage creates information that needs to remain connected to the relevant third-party record.

Lifecycle stage Proposed expectation System capability required
Risk assessment Before engagement and periodically thereafter Consistent risk-tiering model with reassessment triggers for contract renewal, scope changes and incidents
Due diligence Before entering or renewing arrangements, with onsite checks for material arrangements Questionnaire library by risk tier, evidence repository with expiry dates and escalation for stale responses
Contracting Provisions covering audit rights, termination, business continuity and data location Clause checklist linked to the contract record, with approval history for accepted exceptions
Onboarding and monitoring Ongoing monitoring, with independent audits for material arrangements Performance and control monitoring, findings and remediation workflow, linked to the provider's risk rating
Termination Documented exit plans Exit plan for material arrangements, with owner, test date and dependency mapping

The Subcontractor Challenge

A core processing platform may be supplied by one provider while relying on a hyperscaler for infrastructure and an offshore support centre for operational access.

The institution may have one direct contract but several connected dependencies. Understanding those relationships becomes important when assessing data location, access, concentration and continuity risks.

The proposed expectations around material subcontractors therefore make relationship mapping more important. A spreadsheet can record provider names, but connecting providers to subcontractors, business services, risks, controls and continuity plans becomes harder as the number of arrangements increases.

Third-Party Risk and Operational Risk

MAS also consulted on updated Guidelines on Operational Risk Management on 6 March 2026. The proposed update would replace the 2013 guidelines and strengthen expectations around operational risk, resilience, change management and related governance.

The two proposals address overlapping information, including business services, dependencies, risk ownership, controls, incidents and recovery arrangements.

For institutions implementing both frameworks, keeping related information connected can reduce duplicate data collection and reconciliation.

What to Ask a GRC Platform Vendor

Institutions assessing GRC technology should ask:

  • Can a third-party record be linked to risks, controls, incidents, audit findings and continuity plans?
  • Can risk assessments and workflows be changed when regulatory requirements change?
  • Is there an audit trail showing who changed key risk information and when?
  • Can management and board reports use the same underlying records?
  • Does the deployment model support the institution’s hosting and data-location requirements?

The objective is not simply to replace an outsourcing spreadsheet. It is to create a connected record that supports assessment, monitoring, evidence and reporting.

How Corporater Can Support the Proposed TPRM Framework

Corporater’s third-party risk management solution supports third-party risk registers, assessments, monitoring, remediation and reporting. Corporater also states that its platform can integrate data from different sources and offers SaaS, on-premise and private-cloud deployment options.

For the proposed MAS framework, these capabilities can support the processes used to manage third-party assessments, related risks, controls, incidents and reporting. The platform is not a substitute for an institution’s regulatory responsibilities, but it can provide a structured environment for managing the underlying information and workflows.

A Practical Readiness Plan

Institutions can begin preparing before the final guidelines are issued.

Weeks 1 to 3: Identify the wider third-party population using procurement, accounts payable, system access and existing outsourcing records.

Weeks 4 to 6: Apply consistent materiality criteria and document the basis for each rating.

Weeks 7 to 10: Review contracts for material arrangements, focusing on audit rights, termination, business continuity and data location.

Weeks 11 to 14: Identify material subcontractors and key dependencies for higher-risk arrangements.

Weeks 15 to 18: Configure the register, workflows and reporting structure and migrate reviewed data.

Ongoing: Run assessments, monitoring, remediation and exit-plan testing through the same process.

Conclusion

The proposed MAS TPRM Guidelines would widen the focus from traditional outsourcing to third-party arrangements more broadly. For financial institutions, the practical task is to establish a complete view of providers, services, materiality, ownership, subcontractors, controls and supporting evidence.

The proposed six-month transition period should not be treated as the point at which preparation begins. Institutions can start with the data and governance foundations now, then adapt them to the final MAS requirements once issued.

Frequently Asked Questions

When do the MAS third-party risk management guidelines take effect?

MAS proposed a six-month transition period following publication of the final guidelines. The final effective date should be confirmed with MAS before internal compliance deadlines are set.

Do the proposed guidelines replace the MAS outsourcing guidelines?

The proposed TPRM Guidelines would supersede the existing Guidelines on Outsourcing. MAS Notices 658 and 1121 would remain applicable to banks and merchant banks.

What has to be included in the third-party register?

The proposed register would cover material third-party arrangements and material subcontractors where possible, with information needed to identify and assess those arrangements and support ongoing oversight.

Does the proposed framework apply to non-material third parties?

The framework is proportionate. The level of assessment, monitoring and other controls should reflect the nature and materiality of the service and the institution’s size and complexity.

Can a spreadsheet register meet the requirement?

A spreadsheet can maintain third-party information, but institutions should assess whether it can consistently maintain evidence, ownership, review cycles, related risk information and recurring reporting as the population grows.

Speak to a Corporater Implementation Partner in Singapore

Xponential Digital works with financial institutions and regulated firms in Singapore on Corporater implementation for third-party risk, enterprise risk, operational resilience and internal audit. The team can discuss how existing registers, risk processes and supporting evidence could be structured against the proposed MAS TPRM requirements.

Speak to a Corporater Implementation Partner in Singapore

Discuss how existing processes could be structured against the proposed requirements is safer while the MAS framework remains at the proposal stage.

Schedule a call