CPMI-IOSCO consultation — FMIs’ reliance on third-party service providers + Cyber resilience toolkit for FMIs (8 September 2026)

Tag: S-2026-09-08-cpmi-iosco-fmi-third-party-cyber Type: report (two linked consultative documents — a discussion paper and a consultative report) Author(s): BIS Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) Date of source: 2026-09-08 Date ingested: 2026-09-09 Authority weight: medium — international standard-setter (CPMI-IOSCO) consultative documents, retrieved via WebFetch of the BIS publication page; consultative status (not finalised standards), FMI-scoped. Raw file: S-2026-09-08-cpmi-iosco-fmi-third-party-cyber.md. Pages: https://www.bis.org/publications/cpmi-iosco-fmis-reliance-third-party-service-providers-challenges-and-risks and https://www.bis.org/publications/cpmi-iosco-cyber-resilience-toolkit-practical-considerations-fmis.

What it claims

On 8 September 2026 CPMI and IOSCO published, for consultation, two linked documents. The discussion paper FMIs’ reliance on third-party service providers: challenges and risks (22 pages, with a cover note) “identifies and explores the challenges associated with the increased reliance of financial market infrastructures (FMIs) on third-party service providers, particularly for the delivery of critical services.” It “examines how these challenges may amplify risks” and “discusses the importance of FMIs’ management of these risks due to their unique and highly interconnected role in the financial system,” setting out “several questions which provide an opportunity for industry participants to submit feedback on its findings and on potential further engagement.”

The companion consultative report Cyber resilience toolkit: practical considerations for FMIs is published alongside it because the discussion paper “considers cyber resilience at FMIs in the context of risks that may arise through their use of third-party service providers.” Comments on the discussion paper are due by 1 December 2026, submitted to both the BIS CPMI and IOSCO secretariats.

The documents are consultative in status and scoped to financial market infrastructures (payment systems, CSDs, CCPs, trade repositories and similar), not to banks or insurers directly.

Notable quotes

  • “The discussion paper identifies and explores the challenges associated with the increased reliance of financial market infrastructures (FMIs) on third-party service providers, particularly for the delivery of critical services.” (BIS publication page)
  • “It discusses the importance of FMIs’ management of these risks due to their unique and highly interconnected role in the financial system.” (BIS publication page)
  • “[The discussion paper] considers cyber resilience at FMIs in the context of risks that may arise through their use of third-party service providers.” (BIS publication page)

What’s speculative vs. asserted

  • Asserted (CPMI-IOSCO / fact): the 8 September 2026 publication of both documents; their consultative status; the FMI scope; the third-party-reliance-amplifies-risk framing; the pairing of the discussion paper with the cyber-resilience toolkit; the 1 December 2026 comment deadline; the 22-page length of the discussion paper.
  • Consultative / not in force: these are consultation documents, not standards. They pose questions rather than set requirements; content and any resulting guidance may change after consultation.
  • Ingesting-agent inference (not the source’s claim): the specific risks explored, the enumerated consultation questions, the risk taxonomy and the toolkit’s “practical considerations” sit in the three PDFs (discussion paper, toolkit, cover note), not extracted this run ⚠️. The read-across from FMI-scoped guidance to DORA ICT third-party oversight / the DORA Critical ICT Third-Party Provider (CTPP) regime and to the UK FCA/PRA/BoE Critical Third Parties + operational-resilience regimes is the wiki’s assessment, marked [inference] on the synthesis page — the source addresses FMIs, not banks/insurers.

Topics this feeds

  • Operational Resilience and Third Party Risk — a fresh international-standard-setter signal on the third-party-concentration and cyber-resilience threads this page tracks: FMIs’ reliance on third parties for critical services as an amplifier of systemic risk, with cyber resilience explicitly linked to third-party use — read-across (inference) to the DORA CTPP and UK Critical Third Parties threads already documented.

Open questions raised

  • What specific challenges and risk categories does the discussion paper identify for FMI third-party reliance, and how closely do they mirror the DORA CTPP oversight concerns for banks/insurers? (Detail in the unextracted 22-page PDF.)
  • What “practical considerations” does the cyber-resilience toolkit set out, and are any transferable as an assurance checklist beyond FMIs?
  • Will the “potential further engagement” flagged in the discussion paper lead to revised PFMI-aligned expectations or standards for third-party and cyber risk?
  • Does the FMI-scoped framing carry read-across weight for bank/insurer third-party governance, or should it be treated as sector-specific to market infrastructures?