News & Analysis as of

Regulatory Requirements Third-Party Risk

Carlton Fields

NAIC Working Group Begins Sculpting a Framework to Assess Third-Party Data and Models

Carlton Fields on

After taking a brief hiatus since the 2024 Fall National Meeting, the National Association of Insurance Commissioners’ Third-Party Data and Models (H) Working Group began shaping its focus. Based on a regulatory survey of...more

Morgan Lewis - Tech & Sourcing

EBA Proposes Extending Outsourcing Requirements to All Third-Party Arrangements

The European Banking Authority (EBA) recently published a consultation paper (Consultation) that proposes to expand third-party risk management requirements for certain EU-regulated financial entities. The Consultation would...more

Carlton Fields

NAIC Working Group Paints a Picture of Insurer Oversight Expectations

Carlton Fields on

On August 7, 2025, the National Association of Insurance Commissioners’ Annuity Suitability (A) Working Group released draft safe harbor regulatory guidance that paints a clearer picture of how insurers should oversee third...more

NAVEX

[Webinar] Proof in the Process – Why Documentation and Visibility Define Supply Chain Success - September 9th, 10:00 am - 10:45 am...

NAVEX on

The strength of your supply chain isn’t just in the partners you choose – it’s in the records, oversight, and accountability that prove your program works. This webinar explores how effective documentation and visibility...more

Fox Rothschild LLP

FTC Issues GLBA Safeguard Rule FAQs: What Motor Vehicle Dealers Need to Know

Fox Rothschild LLP on

The FTC has issued FAQs for Gramm-Leach-Bliley Act (GLBA) Safeguards Rule compliance by Motor Vehicle Dealers. Here is what you need to know: Step 1: Are you a financial institution? • You are if you either finance (or...more

Ius Laboris

Keeping Workers Safe in Japan: What Employers Need to Know

Ius Laboris on

Japan’s Industrial Safety and Health Act sets clear legal standards for protecting employee health and safety. From medical checks to accident reporting, we take a look at the key employer obligations below....more

Katten Muchin Rosenman LLP

ESAs Publish Guide on Oversight of Critical ICT Third-Party Service Providers under DORA

The European Supervisory Authorities (ESAs) recently published a comprehensive guide (Guide) on the oversight of critical information and communications technology (ICT) third-party service providers (CTPPs) under the EU...more

Hogan Lovells

The EU NIS2 Directive and intra-group IT services

Hogan Lovells on

Key takeaways The EU NIS2 Directive defines cybersecurity obligations also for entities providing IT services only within their own corporate group of companies. To assess the applicability of these obligations, the necessary...more

Mandelbaum Barrett PC

Defending Your Business from AI Legal Risks

Mandelbaum Barrett PC on

AI is no longer just a tool for tech giants. Every day, small and mid-sized companies are using AI for everything from customer service to data analysis and marketing. The potential for growth and efficiency is enormous, but...more

DLA Piper

EU: ENISA Guidelines on Compliance with NIS 2 Directive Published

DLA Piper on

On June 26, 2025, the European Union Agency for Cybersecurity (ENISA) published two sets of guidelines to help businesses ensure their organizational compliance with the NIS2 Directive....more

Secretariat

Five Key Recommendations to Strengthen Cybersecurity in Latin America and the Caribbean

Secretariat on

Cybersecurity is now a core element of legal, regulatory, and business risk management. In Latin America and the Caribbean, organizations face mounting pressure to demonstrate proactive compliance with evolving data...more

A&O Shearman

UK FCA findings on multi-firm review of data quality control frameworks in benchmarks sector

A&O Shearman on

The UK Financial Conduct Authority (FCA) has published a new webpage summarising the findings of its multi-firm review into how benchmark administrators (BMA) manage data-related risks. While the FCA found some firms to...more

Hogan Lovells

Exclusion in Practice: Connected and Associated Persons under the Procurement Act 2023

Hogan Lovells on

In our first article in this series, we explored the expanded mandatory and discretionary exclusion grounds under the Procurement Act 2023 (the "Act"). The Act doesn't just expand the grounds for exclusion. It also changes...more

Pillsbury Winthrop Shaw Pittman LLP

DORA Now Fully in Effect: Financial Entities and Their Service Providers Reach Critical Milestone

With DORA in effect and the European Banking Authority’s updated guidelines for non-ICT services under consultation, financial entities must consider their approach to third-party risk management. After DORA became effective...more

A&O Shearman

EBA consults on draft guidelines for third-party risk management for non-ICT related services

A&O Shearman on

The European Banking Authority (EBA) has published a consultation paper on its draft guidelines for managing third-party risk with regards to non-ICT related services. The guidelines will revise and update its prior 2019...more

Ankura

The Regulatory Roadmap for Third-Party Compliance in Financial Services

Ankura on

In the rapidly evolving financial ecosystem, financial institutions (FIs) increasingly rely on third parties, including Fintech companies, Banking-as-a-Service (BaaS) providers, and other financial service entities—to expand...more

Mitratech Holdings, Inc

The 2025 TPRM Study: Key Findings and Recommendations

The 2025 Mitratech Third-Party Risk Management (TPRM) Study conveys a clear message: the third-party risk landscape is evolving into a complex, interconnected ecosystem — one where every vendor, supplier, and partner plays a...more

Walkers

ESMA principles on third-party risk supervision

Walkers on

On 12 June 2025, ESMA published its principles on third-party risk supervision which are designed to assist supervisory authorities to identify, assess and supervise the third-party risks of EU entities operating across the...more

A&O Shearman

EC adopts Delegated Regulation to delay the application of Basel 3 market risk prudential requirements by an additional year

A&O Shearman on

The European Securities and Markets Authority (ESMA) has published a comprehensive set of principles, accompanied by a press release, aimed at strengthening the supervision of third-party risks across the EU financial sector....more

NAVEX

[Webinar] Supplier Due Diligence – Aligning Supplier Intake with Global Regulatory Requirements - June 17th, 10:00 am - 10:45 am...

NAVEX on

Learn how to align supplier intake with global regulations and build audit-ready onboarding practices in this NAVEX webinar featuring Jan Stappers and Michael Volkov....more

Thomas Fox - Compliance Evangelist

Compliance Tip of the Day: Internal Controls for Third Parties

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance...more

Barnea Jaffa Lande & Co.

DORA for Tech Vendors - What You Should Know (But Haven’t Asked)

DORA (Digital Operational Resilience Act) is an EU regulation that sets rules for how financial entities manage ICT (Information and Communication Technology) risks. It covers areas like cyber resilience, incident reporting,...more

Fenwick & West LLP

5 Things Fintech Startups Need to Know About AML Compliance

Fenwick & West LLP on

Bank-fintech partnerships have transformed the financial services landscape, creating new opportunities and challenges for traditional banking institutions and innovative technology companies alike. ...more

Fenwick & West LLP

Bank-Fintech Partnerships Under Scrutiny: What Fintechs Need to Know About AML Expectations

Fenwick & West LLP on

Bank-fintech partnerships have transformed the financial services landscape, creating new opportunities and challenges for traditional banking institutions and innovative technology companies alike. In a typical arrangement,...more

Alston & Bird

5 Things to Think About When Using AI

Alston & Bird on

What Happened? As the Trump Administration’s deregulatory, pro-innovation approach to emerging technology moves forward, the use of artificial intelligence has taken center stage, and it is clear that the Administration...more

68 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide