FSS Mandates Board Accountability for Financial IT Outsourcing Risks

Key Takeaways
  • South Korea's Financial Supervisory Service announced guidelines on the 29th requiring financial company boards to assume final responsibility for third-party IT outsourcing risks.
  • Financial institutions must establish three-tier control systems and conduct regular inspections at least semi-annually to manage third-party IT risks systematically.
  • Industry associations will implement best practice codes based on FSS guidelines beginning November or later, with ongoing FSS evaluation and continuous improvement.

South Korea's Financial Supervisory Service announced new guidelines on the 29th requiring financial company boards and management to assume final responsibility for IT service outsourcing risks, including hacking incidents at third-party vendors. The FSS developed the framework in collaboration with industry associations across financial sectors to address growing third-party IT risks as digitalization drives more companies to outsource information processing operations. The guidelines aim to strengthen consumer protection amid rising external IT dependencies, with implementation scheduled for November or later following sector-specific code adoption.

FSS Establishes Board Accountability for Third-Party IT Risks

The FSS explicitly designated boards of directors as bearing final responsibility for third-party IT risk management. The guidelines mandate that risk management policies and major supervisory matters require board deliberation and resolution. Management is designated as the entity responsible for establishing, implementing, and maintaining the third-party IT risk management system, with requirements to operate a centralized management department. This department must formulate and execute effective security measures, oversee information processing outsourcing status across business units, and evaluate third-party IT risk status and contract adequacy.

Financial Companies Required to Operate Three-Tier Control System

Financial institutions must establish and operate a three-tier control system consisting of a centralized management department, risk management department, and internal audit department to systematically manage third-party IT risks. Companies must identify third parties' financial soundness and key operational information including services provided, types and volumes of processed information, encryption and communication methods, incident response systems, and computing facilities. Regular inspections (at least once per half-year) are required to maintain updated information. Financial companies must separately designate "major third parties" that significantly impact operations or consumers, applying enhanced risk management to these entities.

Third-Party IT Risk Management Framework Source: Financial Supervisory Service

The guidelines provide specific evaluation items and checklists to effectively assess IT risks for each third party. For identified risks, companies must perform supplementary measures, and when control, mitigation, or transfer proves impossible, contracts must be terminated or the board must decide on continuation.

Contract Lifecycle Risk Management Procedures Standardized

The FSS systematized risk management procedures across contract stages to enable proactive identification and response to third-party IT risks. Pre-contract requirements include verifying service capabilities and information protection management systems through on-site inspections, and reflecting essential matters in contracts including role distribution between outsourcing and contracted parties and liability relationships in case of incidents. During contract periods, companies must regularly inspect implementation status (at least once annually) and prepare contingency plans for system interruptions, backup management systems for business continuity, and exit strategies for contract termination.

Contract Stage Risk Management Process Source: Financial Supervisory Service

Post-contract termination procedures include returning information assets, revoking access privileges, and ensuring complete data destruction.

Industry Associations to Implement Guidelines from November

Industry associations across financial sectors will establish best practice codes based on these guidelines for implementation from November or later. The guidelines present minimum standards and principles for third-party IT risk management, allowing financial companies to flexibly apply them by strengthening or relaxing certain elements according to the importance and risk level of outsourced information processing operations. An FSS official stated that the agency will inspect and evaluate guideline implementation status with industry associations, continuously improving and supplementing deficiencies for ongoing advancement.

FAQ

What did the Financial Supervisory Service announce on the 29th regarding IT outsourcing?

The FSS announced new guidelines requiring financial company boards and management to assume final responsibility for third-party IT risks, including hacking incidents at external vendors. The framework was developed with industry associations to address risks from increasing IT outsourcing as financial digitalization accelerates.

When will financial companies implement the new third-party IT risk guidelines?

Industry associations will establish best practice codes based on the FSS guidelines for implementation from November or later. Companies must operate three-tier control systems and conduct regular inspections at least semi-annually for general monitoring and at least annually for contract implementation status.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments