COLUMN – RANDY PRIEM | The increasing reliance of financial market infrastructures (FMIs) on third-party service providers raises questions that extend well beyond conventional outsourcing. The newly published CPMI-IOSCO discussion paper identifies a number of challenges and risks from concentration and supply-chain complexity to bargaining power and exit planning. The consultation provides an important opportunity for FMIs, third-party service providers and other stakeholders to express their views.
The increasing use of third-party service providers has become an important feature of the FMI landscape. Reliance on third parties can provide significant benefits, including economies of scale, technological modernization, and access to specialised expertise. At the same time, however, it can introduce dependencies into infrastructures that are themselves critical to the functioning of financial markets.
This tension is at the heart of the new CPMI-IOSCO discussion paper, FMIs’ reliance on third-party service providers: challenges and risks, published on 8 September 2026. Drawing on input from FMIs and third-party service providers across multiple jurisdictions through surveys and virtual roundtables, the paper discusses the key risk-management challenges arising from reliance on third parties and seeks stakeholders’ views on whether these challenges are accurate and comprehensive, and whether further support from CPMI-IOSCO would be beneficial.
The timing is particularly relevant. The issues of cloud services, outsourcing, and third-party dependencies have been receiving increasing attention across the post-trade industry. The paper follows my recent PostTrade 360° interview, “Let’s talk about the risky business of third-party outsourcing”, which highlighted concentration and ecosystem risks, including the potential for reduced negotiating power and the difficulties of switching providers. These issues were subsequently at the centre of the PostTrade 360° 2026 panel discussion in Stockholm, “Consultation time: just how should FMIs manage their clouds and other third-party risks?”, held on 3 September. The publication of the CPMI-IOSCO paper now provides a more structured basis for that discussion.
One of the paper’s central observations is that third-party risk cannot necessarily be considered as a purely bilateral relationship between an FMI and its service provider. FMIs operate within highly interconnected ecosystems involving other FMIs, market participants, trading venues, settlement banks, liquidity providers, technology providers, and other critical infrastructures. A disruption originating at a third-party provider may therefore have implications beyond the FMI itself and potentially affect the wider financial system.
This becomes particularly important as reliance on cloud computing and other emerging technologies continues to develop. CPMI-IOSCO notes that reliance on third-party providers for critical services might increase as FMIs modernise their information systems and consider technologies including artificial intelligence, distributed ledger technology, and potentially quantum computing. The question is therefore not whether FMIs should use third-party providers, but how the resulting dependencies can be understood, monitored, and managed in a manner consistent with the systemic importance of FMIs and the Principles for Financial Market Infrastructures (PFMI) set out by CPMI and IOSCO.
Concentration is one important part of this discussion. Dependence on a single provider, or on a small number of providers, can reduce substitutability and create vendor lock-in. At the same time, concentration may exist at the level of the wider financial ecosystem, where multiple FMIs and other financial institutions depend on the same provider. The discussion paper notes that approximately three quarters of the surveyed FMIs considered both market concentration and concentration resulting from choosing a single provider to represent medium or high risks.
A related challenge concerns visibility into supply chains. The paper indicates that while most surveyed FMIs have some visibility of fourth-party providers, only a small proportion have visibility extending further down the chain. Moreover, lack of sufficient access to information and data quality as well as the complexity of technological architectures can make it difficult to identify indirect dependencies and assess their significance.
The discussion around contractual arrangements is equally significant. FMIs participating in the CPMI-IOSCO roundtable highlighted challenges relating to bargaining power, particularly in relationships with large providers. This can make it difficult to obtain or enforce contractual provisions relating to audit rights, information sharing, testing, and other risk-management measures. FMIs retain responsibility for managing risks arising from third-party arrangements, but the contractual tools available to them may in practice be constrained by market structure and their relative negotiating position.
Exit planning illustrates the same point. The ability to substitute a provider is an important mitigation against vendor lock-in, but a formal exit plan does not necessarily mean that an actual exit is feasible in a stressed scenario. The criticality of the service, the complexity of system architectures, and the resources required to migrate can all affect substitutability. The discussion paper consequently identifies exit planning as one of the key challenges requiring further consideration.
Importantly, the discussion paper is framed as an invitation to engage with these issues rather than as a set of predetermined regulatory solutions. For all stakeholders, CPMI-IOSCO asks whether the challenges identified are accurate and comprehensive, whether any challenges are missing or if the discussion is incomplete, what possible solutions could address the challenges, and whether further engagement or policy from CPMI-IOSCO would be helpful. The consultation is not simply asking the industry to confirm that third-party risk exists. The questions provide an opportunity for FMIs, service providers, and other stakeholders to contribute practical experience to the future development of the regulatory and supervisory approach.
The consultation deadline is 1 December 2026.

As a senior official of Belgium’s supervisory market authority and member of CPMI-IOSCO’s steering committee, as well as a scholar, Randy Priem continuously monitors the global financial-stability and investor-protection landscape from the very top of the hill. His PostTrade 360° column lets him share informal observations and reflections underway, on subtopics big or small – find his articles indexed here.
Any views expressed are Randy’s personal, not representing positions of his institutions.













