One in Three FMIs Lack Visibility into Subcontractors

A BIS-IOSCO paper finds one-third of financial market infrastructures cannot see their providers’ subcontractors and lists six third-party risks; consultation closes Dec. 1, 2026.

The Bank for International Settlements and the International Organization of Securities Commissions issued a discussion paper that surveyed financial market infrastructures worldwide and found about one in three cannot see beyond their direct providers to subcontractors. The paper, open for feedback until Dec. 1, 2026, identified six areas of third-party risk that could affect operational resilience.

The first risk is increasing complexity and interconnectedness. FMIs operate in networks of participants, linked FMIs, settlement banks, liquidity providers and vendors; an outage at any node can transmit disruption across the system, with cyber incidents highlighted. The second risk is concentration of third-party providers, described both as vendor lock-in at individual FMIs and as sector-wide concentration when the same providers serve many FMIs. The third risk is opaque supply chains: around a third of surveyed FMIs reported visibility only to direct vendors, not to fourth parties or further subcontractors.

The fourth risk concerns exit planning. Contracts may include termination clauses, but switching providers during a crisis can be impractical when systems are incompatible and migration costs are high. The fifth risk is an imbalance of bargaining power: FMIs, even when systemically important, often have limited leverage with large cloud and infrastructure vendors, which can constrain audit access, testing and service-level terms. The sixth risk is variation in regulatory expectations across jurisdictions, which can require cross-border FMIs to manage overlapping and sometimes inconsistent frameworks.

The paper refers to existing tools and standards. It cites the Financial Stability Board’s third-party risk toolkit, which recommends a lifecycle approach with due diligence, ongoing monitoring and mapping of supply chains to nth parties. The Principles for Financial Market Infrastructures, notably Principle 17 and Annex F, require FMIs to identify, monitor and manage risks from critical providers and to ensure contracts permit access to necessary information. The Basel Committee’s Principles for the Sound Management of Third-Party Risk, finalised in December 2025, require upfront contractual audit and access rights and tested exit plans. IOSCO’s Principles on Outsourcing advise firms to know whether their providers serve other regulated entities and to address concentration accordingly.

The paper recommends FMIs map the providers behind their direct vendors and align those supply-chain maps with contractual protections and tested exit plans. BIS and IOSCO invited comments from regulators and FMIs through the consultation period ending Dec. 1, 2026.

Articles by this author