Raymond Cheung
Chartered Actuary · CRO · Board Adviser · Singapore
Singapore insurance boards have been treating MAS's outsourcing framework as a procurement and legal matter since the guidelines first appeared. MAS has been consistent: the board owns the framework, not the contracts. With the current guidelines already in force and new TPRM rules on the way, the boards that have delegated this to management are carrying a gap they have not recognised.
I sat in on a board risk committee meeting at a Singapore insurer where the outsourcing risk item was a single table: vendor name, service category, date of last review, status green. Fifteen rows, three minutes, moved on. The CRO later told me, privately, that three of those arrangements were with the same group, and that the group itself was the entity the parent company used for its regional technology infrastructure. Nobody in the room had been shown that picture, and the committee's documentation would have given the impression that the outsourcing framework was working exactly as designed.
That is the specific failure mode that MAS's outsourcing framework is designed to prevent, and it is the specific failure mode that a board-as-rubber-stamp approach allows to persist. The guidelines are not a checklist the company secretary holds on behalf of the board. They describe a governance architecture the board is required to own, and the distance between those two descriptions is where risk lives.
What the current guidelines actually say about board responsibilities
The MAS Guidelines on Outsourcing for financial institutions are explicit. The board and senior management are responsible for ensuring that the institution's outsourcing arrangements are subject to appropriate oversight and that the outsourcing does not diminish the institution's ability to fulfil its obligations to MAS and its customers. That is a much higher bar than approving an outsourcing policy and delegating its implementation. It means the board must be capable of forming a genuine judgment about whether the framework is functioning, not merely whether a process was followed.
Under the current guidelines, that means understanding which outsourcing arrangements are material, what due diligence was done before each was entered into, how monitoring is conducted and what findings have emerged, what exit strategies exist for the arrangements the institution cannot afford to have fail, and whether concentration in a small set of service providers or geographies represents a risk the institution has consciously accepted rather than one it has never examined.
“The board's job is not to approve the outsourcing register. It is to be able to tell you, from its own knowledge, which dependencies it could not survive losing and what the plan is if it lost them tomorrow.”
The concentration problem most boards have never been shown
Concentration risk in outsourcing does not show up in a vendor table. It shows up when you look at the table from the right angle. I have seen institutions with twenty separate outsourcing arrangements that were effectively three: one technology group running infrastructure across multiple legal entities with separate contract numbers, one regional treasury services provider holding settlements across multiple products, and one cloud provider underneath three different software-as-a-service vendors that each appeared as separate rows in the register.
The MAS guidelines require institutions to consider concentration risk, including at the service provider and geographic level. In practice, this requires a view that goes one layer deeper than the register: who ultimately controls the service, where is it physically delivered from, and what would happen to multiple arrangements simultaneously in a stress scenario. Most boards have seen neither the layered picture nor the stress test.
Sub-contracting: the fourth-party problem boards have stopped asking about
The current guidelines require institutions to know who their service providers are sub-contracting to, to have the right to approve material sub-contracting changes, and to ensure that sub-contractors are subject to standards comparable to the service provider itself. That is the requirement on paper. In practice, the enforcement mechanism is a contractual provision, and many older outsourcing contracts do not include sub-contracting notification or approval rights that would meet the current standard.
I have reviewed outsourcing contracts for Singapore insurers that were signed before the current guidelines were finalized, are still in place, and have never been renegotiated to include sub-contracting controls. The institution complied at the time of signing. Whether it complies today, under the standard the current guidelines set, is a different question. The board is unlikely to know the answer unless it has asked it directly, because the gap does not appear in the standard reporting format.
Exit strategies: the part that disappears after the contract is signed
MAS requires institutions to maintain exit strategies for material outsourcing arrangements. The intent is that if a service provider fails, is sold, or simply becomes unacceptable, the institution can substitute without impairing the services it owes to policyholders and to the regulator. Exit strategies are typically written when a contract is first signed, at a moment when the institution is optimistic about the relationship and the alternative providers are well-known. They are rarely reviewed when the relationship matures and the switching costs have increased, when the alternative providers have contracted, or when the service has become embedded in the institution's processes in ways that make it harder to unwind than the original plan assumed.
What the board should be asking is not whether an exit strategy exists. It is whether the exit strategy is current, whether it has been tested against the actual operational state of the arrangement rather than the state it was in when originally signed, and whether the board is confident the institution could execute it under adverse conditions rather than under the benign ones assumed in the document.
What the new TPRM guidelines add
MAS published its proposed Guidelines on Third-Party Risk Management in March 2026, which will supersede the current outsourcing guidelines. The single most significant change is scope: the new framework applies to all third-party services the institution relies on, not only formal outsourcing arrangements. The board oversight obligations are the same in structure, but they now apply to a materially larger population of arrangements, including technology services, data services, and advisory relationships that were previously managed under commercial rather than risk frameworks.
The practical implication is that boards which have been treating the outsourcing register as their full picture of third-party risk will discover, under the new framework, that the register covers a subset of the actual exposure. The institutions that will navigate the six-month transition period most cleanly are those whose boards already understand the full third-party dependency picture, rather than only the subset that carries a formal outsourcing label.
What the board should actually own
- A concentration view of the outsourcing register, not the register itself: which arrangements share an ultimate counterparty, which share a geography, and what the correlated stress scenario looks like across the portfolio, not the individual rows.
- An annual confirmation from management that sub-contracting provisions in material contracts meet the current guidelines, not the version in force when the contracts were signed.
- A tested exit strategy for each material arrangement: tested against the current operational state of the arrangement, not the original design, with explicit board sign-off on whether the institution accepts the switching risk where a credible exit does not exist.
- A view on the inventory of non-outsourcing third-party services that will fall under the proposed TPRM framework, and a plan for bringing that population into the governance framework before the new guidelines take effect.
- A standing question in the board risk committee: has any material outsourcing arrangement changed in a way that affects its risk profile, exit strategy or concentration picture since the last review? Ask it as a question requiring a direct answer rather than a standing green on the register.
I have seen outsourcing governance done well and I have seen it done as theatre, and the difference is not in the quality of the documentation. It is in whether the board believes it owns the outcome rather than the process. A board that has genuinely engaged with concentration, sub-contracting and exit can have a harder conversation with management when something goes wrong. A board that has only seen the register cannot.
Common Questions
What does MAS's outsourcing framework require of Singapore insurance boards?
Under the MAS Guidelines on Outsourcing, the board and senior management are responsible for ensuring that outsourcing arrangements are subject to appropriate oversight and do not diminish the institution's ability to fulfil obligations to MAS and its customers. That means the board must be capable of forming a genuine judgment about the framework's effectiveness, not merely confirming a process was run. Specific expectations include oversight of material outsourcing determinations, due diligence, concentration risk, sub-contractor management, and exit strategy adequacy.
What is concentration risk in outsourcing and why does it matter for Singapore insurance boards?
Concentration risk in outsourcing arises when multiple arrangements share an ultimate service provider, a geography, or an infrastructure provider at a layer the institution does not directly contract with. MAS requires institutions to assess concentration risk explicitly. A board that only reviews the outsourcing register by rows will miss concentration that becomes visible only when the register is aggregated across ultimate counterparties. The failure mode is discovering the concentration in a stress scenario rather than in a regular governance review.
How do MAS's proposed TPRM guidelines change the board's outsourcing obligations?
The proposed Guidelines on Third-Party Risk Management, which will supersede the current outsourcing guidelines once finalised, extend the framework to cover all third-party services the institution relies on, not only formal outsourcing arrangements. The board governance obligations are structurally the same, but they apply to a larger population that includes technology services, data services and advisory relationships previously managed outside the outsourcing framework. A six-month transition period is proposed from the date of issuance.
What should a Singapore insurance board ask about its exit strategies for outsourced services?
Ask whether each exit strategy has been reviewed against the current operational state of the arrangement, not just the design-time document, and whether the board could actually execute it under adverse rather than benign conditions. Specifically: has the service become more embedded since the strategy was written, has the number of credible substitute providers changed, and has the contractual switching mechanism been tested rather than assumed? MAS requires exit strategies for material arrangements, but requires ones that work in practice, not ones that satisfy a documentation standard.
Related insights
About the author
Raymond Cheung is a Chartered Actuary, C-suite executive and board adviser with more than 20 years of experience across Asia in risk management, insurance, ESG and corporate governance. He is the CEO of CER Consultancy and an accredited trainer at SMU Academy and the Singapore College of Insurance.