Back to Insights
Regulation4 min readOctober 2026

MAS's New Third-Party Risk Guidelines Are Not an IT Problem. They Are a Board Problem.

RC

Raymond Cheung

Chartered Actuary · CRO · Board Adviser · Singapore

MAS's proposed Guidelines on Third-Party Risk Management, which replace the familiar outsourcing guidelines with a framework covering every third-party relationship an insurer holds, are still in consultation-to-final transition. Most boards have delegated them to procurement and IT. That is the wrong delegation, and MAS has been explicit about why.

MAS published its consultation paper on proposed Guidelines on Third-Party Risk Management in March 2026. The consultation closed in April. The final guidelines have not yet been issued, but a six-month transition period from issue date is already built in, which means for any insurer whose compliance planning starts at publication rather than before it, the preparation window is already shorter than it looks.

The scope change that boards are underestimating

The existing outsourcing guidelines, the ones Singapore insurers have been complying with for years, apply to formal outsourcing arrangements. The proposed TPRM guidelines apply to all third-party services the institution relies on. That is not a refinement. It is a different scope entirely. If your data analytics platform is operated by a third party but was never categorised as an outsourced service because the contract was signed by the business rather than IT, it is in scope under the new framework in a way it was not before. Most insurers I speak with have not completed that inventory exercise.

“MAS expects the board to ensure sound governance and risk management of third-party relationships. That is not language directed at procurement or IT. It is language directed at the board.”

What the guidelines explicitly place on the board

The proposed guidelines are direct. MAS expects the board and senior management to establish a third-party risk management framework aligned with the institution's operational risk management framework, maintain a strategy consistent with other relevant strategies, and ensure adequate processes for a comprehensive firm-wide view of third-party risk exposures. The register of all material third-party arrangements, including material sub-contractors, is to be submitted to MAS semi-annually. The board owns the framework that makes those submissions credible.

Three things I would want the board to own personally

  • A genuine firm-wide inventory of material third-party relationships, not the outsourcing register that already exists, but the broader population that falls under the new scope. This exercise will find arrangements the board has never been shown and some where concentration risk is higher than the existing register suggests.
  • A clear position on concentration: which service provider or geographic concentration, if it failed, would impair an obligation the board cannot suspend. That is the test MAS is applying, and it is a more exacting test than the standard materiality threshold used in existing outsourcing frameworks.
  • Sub-contracting visibility. The guidelines require service providers to notify the institution before engaging material sub-contractors and to cascade contractual requirements to those sub-contractors. In practice, most institutions do not currently have contractual provisions that give them this visibility, let alone enforce it. The board should know which critical services have this gap and when it will be closed.

The transition period is the part boards keep misreading. Six months from issue sounds generous. But the clock starts from publication of the final guidelines, not from when the consultation was announced, and the practical work, renegotiating service agreements, completing due diligence on providers the institution has not previously assessed under a risk lens, building the register, getting board-level sign-off on the framework, is not six months of effort in series. It is concurrent work streams, some of which require counterparty cooperation, which is not under the institution's control.

My observation, both from CRO positions and from board advisory work, is that institutions that treat this as an IT project will spend the transition period discovering that the board does not have a complete picture of what it depends on externally, and that some of what it depends on has contractual terms that will not survive the new requirements without renegotiation. That is the institution that faces the transition deadline with open items rather than a closed framework. The boards that engage with this now, before the final guidelines are issued, are the ones that will not be scrambling in the six months after.

Common Questions

What are MAS's proposed Third-Party Risk Management Guidelines and how do they differ from the outsourcing guidelines?

MAS published a consultation paper on proposed TPRM Guidelines in March 2026, with the consultation closing in April. Unlike the existing Guidelines on Outsourcing, which apply only to formal outsourcing arrangements, the proposed TPRM guidelines apply to all third-party services a financial institution relies on. This materially expands scope. Final guidelines are pending, with a six-month transition period from issuance.

What does MAS's proposed TPRM framework require of boards at Singapore insurers?

MAS is explicit. The board and senior management are expected to establish a third-party risk management framework aligned with the operational risk management framework, maintain a TPRM strategy, and ensure processes for a firm-wide view of third-party risk. Material third-party arrangements, including material sub-contractors, must be reported to MAS semi-annually. The board is accountable for the integrity of that framework.

What should a Singapore insurance board do before MAS's final TPRM guidelines are issued?

Three things. First, conduct a proper inventory of all third-party service reliances, not just formal outsourcing, to understand what will fall under the new scope. Second, identify concentration risk at the service-provider and geography level. Third, review whether current service contracts include the sub-contractor notification and requirement-cascading provisions the new guidelines will require. Renegotiating those contracts takes time and counterparty cooperation, so work that cannot wait for publication should start now.

Related insights

About the author

Raymond Cheung is a Chartered Actuary, C-suite executive and board adviser with more than 20 years of experience across Asia in risk management, insurance, ESG and corporate governance. He is the CEO of CER Consultancy and an accredited trainer at SMU Academy and the Singapore College of Insurance.

All insights