BCBS — Principles for the sound management of third-party risk (d605)
Tag: S-2025-12-10-bcbs-d605
Type: report
Author(s): Basel Committee on Banking Supervision
Date of source: 2025-12-10 (publication of d605)
Date ingested: 2026-05-17 (consolidated from multiple Open Brain restatements 20 Mar – 10 May 2026)
Authority weight: high — final Basel principles paper.
Raw file: Open Brain corpus snapshot at /_raw_sources/open-brain-2026-05-17-corpus.md. External URLs: https://www.bis.org/press/p251119.htm and https://www.bis.org/press/p251210.htm
What it claims
The Basel Committee finalised Principles for the sound management of third-party risk (BCBS d605) on 10 December 2025, following the November 2025 approval (press release p251119). The paper sets out 12 principles — 9 for banks and 3 for supervisors — as a technology-agnostic common baseline. The key conceptual move is to broaden “outsourcing” into a wider third-party risk concept, superseding the 2005 Joint Forum Outsourcing paper. Banks must retain clear accountability for all activities performed by third parties even where fully outsourced, with robust governance frameworks, comprehensive risk assessments, and ongoing monitoring throughout the third-party relationship lifecycle. The principles align directly with DORA third-party oversight obligations and the FCA’s Critical Third Parties regime.
Notable quotes
No verbatim quotes captured — Open Brain ingestions all rely on WebSearch summaries of bis.org.
What’s speculative vs. asserted
- Asserted: the 12-principle structure, the supersession of the 2005 Joint Forum paper, alignment with DORA and the FCA Critical Third Parties regime, and the broadening from outsourcing to third-party risk.
- Not speculative — this is a finalised paper.
Topics this feeds
- Operational Resilience and Third Party Risk
- BCBS AI Governance Framework — third-party AI / GPAI providers fall under d605 scope.
Open questions raised
- How national supervisors will translate the principles into local rule changes (UK, EU member states already operate parallel regimes via FCA, DORA).
- Treatment of GPAI providers as “critical” third parties when deployed in regulated workflows.
Ingestion note
Consolidates Open Brain thoughts dated 5/10, 4/26, 4/14, 4/9, 4/2, 3/31, 3/20, all summarising the same publication.