# Banks must bolster supply chain resilience ahead of new outsourcing regulations
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-04-26
Category: BANKING
Category URL: https://financedigest.com/category/banking
Meta Title: Mitigating Supplier Risks in UK Banks: A Guide to Compliance
Meta Description: Learn how UK banks can mitigate supplier risks and comply with upcoming Prudential Regulation Authority rules to avoid financial impact and potential penalties.
URL: https://financedigest.com/banks-must-bolster-supply-chain-resilience-ahead-of-new-outsourcing-regulationshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/supply-chain-resilience-1736838408844-compressed.jpg)

_By **Alex Saric,** Smart Procurement Expert at Ivalua_

As UK banks try to keep up with the pace of transformation, meet customer expectations and drive efficiency, outsourcers are becoming embedded in key areas from people to technology and processes, helping to share the load.

But sharing the load also means sharing the risk. [Outsourcer failure can expose banks](https://www.financedigest.com/in-a-rising-market-are-banking-outsourcers-pulling-their-weight.html "In a rising market, are banking outsourcers pulling their weight?") to all manner of risks across the supply chain, from poor environmental practices to modern slavery, corruption, or data privacy breaches. The cost for outsourcer failure is skyrocketing too. Deloitte found [almost half of organisations (46%)](https://www2.deloitte.com/content/dam/Deloitte/xe/Documents/risk/Deloitte%20Third-Party%20Risk%20Management%20Global%20Survey%20Report%202020.pdf) said the financial impact of third-party or subcontractor failure has _at least_ _doubled_ over the last five years.

At the same time, the [upcoming Prudential Regulation Authority (PRA)](https://www.bankofengland.co.uk/prudential-regulation/publication/2019/outsourcing-and-third-party-risk-management) regulations are set to increase banks’ accountability for risk when identifying, selecting and managing third-parties. This could be an astronomical task for the procurement department, but it’s an essential one. [Banks need](https://www.financedigest.com/britains-digital-banks-need-support-amid-banking-turmoil-trade-body.html "Britain’s digital banks need support amid banking turmoil – trade body") to make sure they are preparing for the new rules efficiently.

Those who don’t comply could face dismissal of top management, limitations on their banking activity or even suspension of banking authorisation. What’s more, banks that don’t improve resilience will be less able to combat supplier risk at a time where [third-party data breaches](https://www.reuters.com/article/us-usa-solarwinds-cyber-idUSKBN28N0Y7) and [CSR issues](https://www.reuters.com/article/us-boohoo-suppliers-idUSKBN2BH0R4) are rife.

**A new set of rules**

To reduce supplier risk and prepare for the incoming PRA rules, [banks must](https://www.financedigest.com/why-finance-professionals-must-bank-on-a-journey-to-the-cloud.html "Why finance professionals must bank on a journey to the cloud") drastically improve visibility into their suppliers and other third-parties. They must also put due diligence and business continuity plans in place, so they can identify [risks ahead](https://www.financedigest.com/staying-ahead-of-risk-this-black-friday.html "Staying Ahead of Risk This Black Friday") of time.

Essentially, the PRA [says the rules will “improve the ability of firms](https://www.financedigest.com/over-a-dozen-chinese-based-firms-say-they-have-minimal-exposure-to-svb.html "Over a dozen Chinese-based firms say they have minimal exposure to SVB") to manage relevant risks and facilitate oversight of outsourced and third-party service providers by firms and the PRA.” This will help financial institutions to make informed decisions and ensure records are accurate and easy to audit.

Practically, [financial institutions](https://www.financedigest.com/what-the-future-holds-for-financial-institutions-in-2023.html "What the Future Holds For Financial Institutions in 2023") will need to bolster their record keeping and governance, and develop detailed processes for risk assessments on all suppliers and outsourcers. They must also ensure contracts always contain clear descriptions of outsourced functions, renewal dates and termination notices.

The 2019 [European Banking Authority Outsourcing Guidelines](https://www.ivalua.com/blog/eba-outsourcing-guidelines/) covers a lot of these record-keeping needs, requiring an up-to-date register of information on all outsourcing arrangements. But banks have never had to delve so deeply into how their outsourcers prepare for, manage and react to disruption.

**Increasing governance and control**

To improve visibility for each outsourced project, [banks must ensure they have a digitalrepository of policy](https://www.financedigest.com/what-to-make-of-the-headlines-brexit-and-bank-of-england-policy-eba-bank-stress-tests.html "What to make of the headlines? Brexit and Bank of England policy, EBA bank stress tests") documents, specifying expiry dates and notifying stakeholders when an important date is approaching. To [maximise the value](https://www.financedigest.com/5-ways-to-maximise-the-value-of-instant-payments.html "5 ways to maximise the value of instant payments") of this additional reporting, banks must gather this data into a single repository, and use it to enforce policies across the complete Source-to-Pay process.

For critical outsourced activities, banks should also put specific approval workflows in place, including involving compliance teams when needed, [launching risk](https://www.financedigest.com/aon-launches-new-catastrophe-model-to-manage-the-risk-of-icelands-most-disastrous-peril-earthquake.html "Aon launches new catastrophe model to manage the risk of Iceland’s most disastrous peril: Earthquake") assessments, and ensuring that dedicated clauses are signed off by suppliers. Improvement plans should be automated and auditable when gaps are identified, to both ensure issues are rectified and prove that the bank acted responsibly.

[Banks must continue to improve](https://www.financedigest.com/struggling-banks-need-to-modernise-and-improve-software-quality-management.html "Struggling Banks Need to Modernise and Improve Software Quality Management") their auditory capabilities so they can show if an outsourcer is critical or non-critical, onshore or offshore. But, the new rules will require them to go further; [banks must collect data to mitigate any potential risks](https://www.financedigest.com/governments-and-central-banks-risk-inflation-bank-of-england-has-done-its-bit-now-the-politicians-turn.html "Governments and central banks risk inflation, Bank of England has done its bit, now the politicians’ turn"). This includes data on contract audit timings, identified alternate suppliers, substitutability, and re-integration assessment plans. So, procurement teams need to ensure they can gather this information quickly.

**Going beyond tier one suppliers**

It’s no longer enough to track for [supply chain risk](https://www.financedigest.com/minimising-supply-chain-cyber-risks-by-asking-the-right-questions.html "MINIMISING SUPPLY CHAIN CYBER RISKS BY ASKING THE RIGHT QUESTIONS") in direct suppliers. Banks must strictly and permanently assess, manage and mitigate their third-party risk, including subcontractor exposure, also known as fourth-party risk, before entering into an agreement.

To track outsourcing risk at such a granular level, organisations [must establish comprehensive supplier risk mapping with a direct view into the subcontractors and their risk level](https://www.financedigest.com/2016-must-be-the-year-of-board-level-transparency-and-good-governance.html "2016 must be the year of board level transparency and good governance"). This will create a complete view of risk, aggregating internal risk data sources, and external sources like [Ecovadis](https://ecovadis.com/), which rates suppliers on CSR and sustainable procurement practices. Risk maps can also be designed so procurement leaders and stakeholders will receive contextual alerts in case of a [rising](https://www.financedigest.com/ecb-governors-see-rising-risk-of-rate-hitting-2-to-curb-inflation-sources.html "ECB governors see rising risk of rate hitting 2% to curb inflation – sources") risk exposure, giving them a head start to start forming mitigation plans as soon as possible.

**A smarter choice**

As the cost and frequency of outsourcing failure rises, [banks must choose the right technology](https://www.financedigest.com/the-rise-of-biometric-technology-in-banking.html "The rise of biometric technology in banking") to prepare effectively for upcoming PRA regulations and reduce supplier risk. If not, it could cost them huge amounts of additional time and resources and increase risk exposure.

This means taking a smart approach to procurement, implementing the right tools to manage supplier data. Banks need a platform that can manage, automate and drive efficiency across the sourcing, contracting, [supplier management and contract](https://www.financedigest.com/french-energy-suppliers-will-let-struggling-bakers-renegotiate-contracts-le-maire.html "French energy suppliers will let struggling bakers renegotiate contracts – Le Maire") assessment stage that is compliant with regulations. What’s more, as processes are digitised, they can be easily configured to accommodate updated regulations or changes in outsourcing contracts, avoiding future disruption.

Armed with greater visibility and flexibility across the [supply chain](https://www.financedigest.com/5-steps-to-successful-supply-chain-finance.html "5 Steps to successful supply chain finance"), financial institutions can reduce risk when onboarding, managing and ending outsourcing relationships. Ultimately, this will speed up the onboarding process, saving time and cost, while also reducing risk of non-compliance.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

