Compliance

Third-party service provider

External vendor providing technology or outsourced services.

Definitions (2)

An external entity engaged to provide technology, infrastructure, or other services to a CME, including subcontractors; subject to due diligence, contractual security/data protection clauses, audit rights, subcontractor mapping and contingency/exit arrangements under the GTRM. The term frames vendor governance and outsourcing obligations.

An external entity engaged by a financial institution to provide services, functions or systems (including cloud service providers) which may create outsourcing and third‑party risks; the PD requires due diligence, contractual protections, monitoring, SLAs and exit strategies for such providers.