Sai360
Integration of Vendor Risk and Business Resilience Programs
Pages
10
Time to read
19 mins
Publication
Language
English
Pages
10
Time to read
19 mins
Publication
Language
English
This technical report discusses the integration of Vendor Risk Management (VRM) and Business Continuity Management (BCM) programs within financial services organizations. It outlines the increasing frequency of cyber breaches via third-party vendors and the necessity for organizations to develop management frameworks for risk. The report references the Basel Committee on Banking Supervision's 2018 publication on cyber-resilience, emphasizing the importance of aligning VRM and BCM to enhance operational resilience. It details how VRM intersects with BCM, particularly when vendor access poses risks to continuity and recovery. The report highlights the need for financial services organizations to assess vendor cybersecurity practices and recovery capabilities. It also addresses the regulatory expectations for managing third-party arrangements and the importance of conducting recovery tests. The document serves as a roadmap for organizations to close gaps between cybersecurity, vendor risk, and business continuity, ultimately aiming to reduce risks and improve resilience against cyber threats.