Cyber toolkit tackles FMIs’ third-party vendor risk

cyber

The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) have published a new toolkit and a discussion paper addressing cyber resilience and third-party dependency risks across financial market infrastructures (FMIs).

The toolkit, titled Cyber resilience toolkit: practical considerations for FMIs, sets out a series of voluntary, non-binding measures intended to help FMIs reinforce their cyber resilience frameworks.

It is built to support the operational resilience elements of the CPMI-IOSCO Principles for Financial Market Infrastructures (PFMI) and is designed to sit alongside the existing 2016 CPMI-IOSCO Guidance on cyber resilience for financial market infrastructures, rather than replace it.

Alongside the toolkit, the two bodies released a separate paper, FMIs’ reliance on third-party service providers: challenges and risks, which sets out the risks that arise when FMIs depend on outside vendors to deliver critical services.

The paper flags this dependency as a growing area of concern for the stability of market infrastructure and lays out a series of questions inviting feedback from stakeholders on the risks identified, as well as on how further regulatory engagement might be shaped.

CPMI operates under the Bank for International Settlements and works to strengthen and promote the safety and efficiency of payment, clearing and settlement systems worldwide. IOSCO brings together the world’s securities regulators and sets international standards for the securities sector, working to protect investors and ensure markets remain fair, efficient and transparent.

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.