Outsourcing & Third-Party Risk Guidance – Neves Licensing Authority
Supervisory Guidance

Outsourcing & Third-Party Risk Guidance

Guidance Note • GN-OTPR-01 • Effective 2025

This Guidance sets supervisory expectations for licensed and registered persons when outsourcing material functions or relying on third parties (including technology, cloud, payments, KYC/KYB vendors, and compliance providers). Outsourcing does not reduce accountability: regulated responsibility stays with the licensee.

Outsourcing Third-party risk Operational resilience

Overview

This Guidance is principles-based and should be applied proportionately to your size, complexity, risk profile, and the materiality of the outsourced activity. The Authority may request evidence of compliance during supervision.

What this Guidance covers

  • Governance and accountability for outsourcing decisions
  • Materiality assessment and risk classification
  • Due diligence before engagement and ongoing monitoring
  • Contract minimums (audit rights, SLAs, security, incident duties)
  • Concentration risk, sub-outsourcing, and exit planning
  • Cloud, data protection, and operational resilience expectations
Section A
Definitions & Scope
A1. Outsourcing and third-party arrangements

Outsourcing includes delegation of a function, process, service, or activity to a third party that the licensee would otherwise perform itself, including intra-group arrangements where relevant.

A2. Material outsourcing

A function is “material” where failure or degradation would materially impact: continuity of service; system integrity; confidentiality or data security; client outcomes; compliance; or the Authority’s ability to supervise.

A3. Proportionality

Firms must apply this Guidance proportionately. Higher-risk and material arrangements require deeper governance, stronger contractual protections, and more frequent monitoring.

Section B
Governance & Accountability
B1. Board and senior management responsibility

The licensee remains fully responsible for outsourced activities. Governance must define accountable owners, approval thresholds, and escalation processes for outsourcing decisions and incidents.

B2. Outsourcing policy

Maintain an outsourcing/third-party risk policy that covers: materiality criteria, due diligence, contract standards, oversight cadence, security controls, incident reporting, sub-outsourcing, and exit planning.

B3. Register of outsourcing arrangements

Maintain a current register of third-party arrangements including: provider, service, data types, locations, materiality rating, key SLAs, renewal dates, sub-processors, and exit plans.

Section C
Risk Assessment & Due Diligence
C1. Pre-engagement risk assessment

Before engaging a provider, assess: operational impact, data exposure, cyber risk, compliance impact, service criticality, portability, concentration risk, and substitutability.

C2. Due diligence minimums

Due diligence should include, as applicable:

  1. corporate and ownership checks (including UBO/controller identification where relevant);
  2. financial stability and continuity indicators;
  3. security posture (certifications, controls, penetration testing summaries, vulnerability management);
  4. data protection posture and data residency capabilities;
  5. BCP/DR capability, RTO/RPO targets and test evidence;
  6. service delivery track record and incident history;
  7. sub-processor mapping and control over onward outsourcing.
C3. Risk classification

Classify third parties (e.g., low/medium/high; material/non-material) and set oversight requirements accordingly. Material/high-risk services must have enhanced controls and documented approvals.

Section D
Contracting Standards
D1. Contract minimum clauses

Contracts for material outsourcing should include:

  1. clear service description, responsibilities, and control boundaries;
  2. service levels (availability, support hours, response times, performance metrics);
  3. security obligations (access control, encryption, logging, vulnerability management);
  4. incident notification obligations with timeframes and cooperation duties;
  5. audit rights (direct or via independent assurance reports), including regulator access where applicable;
  6. sub-outsourcing controls (approval rights and full visibility of sub-processors);
  7. data handling terms (locations, retention, deletion, breach notification);
  8. business continuity and disaster recovery commitments;
  9. exit/termination rights, portability, and transition assistance;
  10. liability, indemnities, and remediation obligations proportionate to risk.
D2. Change management

Contracts should require advance notice for material changes (sub-processors, locations, architecture, security posture) and allow the licensee to object or exit where risks become unacceptable.

Section E
Ongoing Monitoring & Assurance
E1. Performance and risk monitoring

Monitor performance against SLAs, security posture, incident trends, and control effectiveness. Material arrangements should have scheduled reviews and documented outcomes.

E2. Independent assurance

For higher-risk services, obtain independent assurance where available (e.g., SOC reports, ISO certifications, audit summaries) and evaluate exceptions with remediation tracking.

E3. Incident management

Ensure incident playbooks include third-party coordination, contact points, and clear obligations for evidence preservation, root-cause analysis, and timelines for corrective actions.

Section F
Concentration Risk, Sub-Outsourcing & Resilience
F1. Concentration risk

Identify dependencies on single providers, regions, or infrastructures (including cloud concentration). Where concentration is high, implement mitigants (multi-vendor strategy, portability planning, enhanced resilience testing).

F2. Sub-outsourcing

Licensees must have visibility into sub-processors and retain control through approval rights, security standards, and contractual flow-down obligations.

F3. Exit planning

Maintain exit plans for material providers, including data portability, transition timelines, minimum notice periods, replacement options, and tested restoration of service.

Section G
Cloud, Data Protection & Cross-Border Considerations
G1. Data classification and minimisation

Identify data types processed by third parties and apply data minimisation. Apply stronger controls for sensitive data (identity documents, financial data, KYC records, transaction data).

G2. Data location and access

Document where data is stored/processed, who can access it, and how access is controlled and logged. Ensure appropriate controls for cross-border processing and lawful disclosure requests.

G3. Encryption and key management

For material services, implement encryption in transit and at rest. Where feasible, adopt robust key management practices and define responsibilities for key custody and rotation.

Section H
Supervisory Engagement & Evidence
H1. Evidence the Authority may request

During supervision, the Authority may request evidence such as:

  1. outsourcing policy and governance approvals;
  2. outsourcing register and materiality assessments;
  3. due diligence pack and ongoing monitoring records;
  4. contracts (or key clause extracts) for material providers;
  5. BCP/DR test results, incident reports and remediation tracking;
  6. sub-processor lists and change notifications.
H2. Notification of material changes

Licensees should notify the Authority of material outsourcing changes or significant third-party incidents where these may impact continuity, integrity, confidentiality, or compliance.

Section I
Effective Date & Implementation
I1. Implementation

This Guidance is effective upon publication. Licensees should implement proportionate controls promptly and ensure material arrangements are reviewed and uplifted where gaps exist.

I2. Status of Guidance

This Guidance supplements the supervisory framework and supports risk-based oversight. It does not replace or override obligations under applicable Acts, license conditions, or codes.