South Korea's Financial Supervisory Service announced new guidelines on the 29th requiring financial company boards and management to assume final responsibility for IT service outsourcing risks, including hacking incidents at third-party vendors. The FSS developed the framework in collaboration with industry associations across financial sectors to address growing third-party IT risks as digitalization drives more companies to outsource information processing operations. The guidelines aim to strengthen consumer protection amid rising external IT dependencies, with implementation scheduled for November or later following sector-specific code adoption.
FSS Establishes Board Accountability for Third-Party IT Risks
The FSS explicitly designated boards of directors as bearing final responsibility for third-party IT risk management. The guidelines mandate that risk management policies and major supervisory matters require board deliberation and resolution. Management is designated as the entity responsible for establishing, implementing, and maintaining the third-party IT risk management system, with requirements to operate a centralized management department. This department must formulate and execute effective security measures, oversee information processing outsourcing status across business units, and evaluate third-party IT risk status and contract adequacy.
Financial Companies Required to Operate Three-Tier Control System
Financial institutions must establish and operate a three-tier control system consisting of a centralized management department, risk management department, and internal audit department to systematically manage third-party IT risks. Companies must identify third parties' financial soundness and key operational information including services provided, types and volumes of processed information, encryption and communication methods, incident response systems, and computing facilities. Regular inspections (at least once per half-year) are required to maintain updated information. Financial companies must separately designate "major third parties" that significantly impact operations or consumers, applying enhanced risk management to these entities.
Source: Financial Supervisory Service
The guidelines provide specific evaluation items and checklists to effectively assess IT risks for each third party. For identified risks, companies must perform supplementary measures, and when control, mitigation, or transfer proves impossible, contracts must be terminated or the board must decide on continuation.
Contract Lifecycle Risk Management Procedures Standardized
The FSS systematized risk management procedures across contract stages to enable proactive identification and response to third-party IT risks. Pre-contract requirements include verifying service capabilities and information protection management systems through on-site inspections, and reflecting essential matters in contracts including role distribution between outsourcing and contracted parties and liability relationships in case of incidents. During contract periods, companies must regularly inspect implementation status (at least once annually) and prepare contingency plans for system interruptions, backup management systems for business continuity, and exit strategies for contract termination.
Source: Financial Supervisory Service
Post-contract termination procedures include returning information assets, revoking access privileges, and ensuring complete data destruction.
Industry Associations to Implement Guidelines from November
Industry associations across financial sectors will establish best practice codes based on these guidelines for implementation from November or later. The guidelines present minimum standards and principles for third-party IT risk management, allowing financial companies to flexibly apply them by strengthening or relaxing certain elements according to the importance and risk level of outsourced information processing operations. An FSS official stated that the agency will inspect and evaluate guideline implementation status with industry associations, continuously improving and supplementing deficiencies for ongoing advancement.
FAQ
What did the Financial Supervisory Service announce on the 29th regarding IT outsourcing?
The FSS announced new guidelines requiring financial company boards and management to assume final responsibility for third-party IT risks, including hacking incidents at external vendors. The framework was developed with industry associations to address risks from increasing IT outsourcing as financial digitalization accelerates.
When will financial companies implement the new third-party IT risk guidelines?
Industry associations will establish best practice codes based on the FSS guidelines for implementation from November or later. Companies must operate three-tier control systems and conduct regular inspections at least semi-annually for general monitoring and at least annually for contract implementation status.