DistantNews
Support us
๐Ÿ‡ฐ๐Ÿ‡ท South Korea /Technology

Financial firms' boards to bear final responsibility for outsourced IT risks

From Hankyoreh · () Korean

Translated from Korean, summarized and contextualized by DistantNews.

At a glance

News Sources not specified New plan
  • Financial companies are now responsible for IT risks associated with outsourced vendors, not just their own security.
  • The Financial Supervisory Service has issued guidelines for managing third-party IT risks, to be implemented by November.
  • The guidelines mandate board-level responsibility for IT risk management and require detailed vendor assessments.

Financial companies must now take ultimate responsibility for IT risks stemming from outsourced vendors, a shift from solely focusing on their internal security measures. This directive follows a recent incident where personal information of over 17,000 Woori Bank customers was leaked due to the negligence of an employee from an external development company.

The Financial Supervisory Service (FSS) announced on June 29 the establishment of "Guidelines for Managing Third-Party Information Technology (IT) Risks for Financial Companies." These guidelines aim to systematically manage the risks associated with the increasing reliance on external services like cloud computing and Software as a Service (SaaS) due to the digital transformation of the financial sector.

The guidelines stipulate that the board of directors holds the final responsibility for managing third-party IT risks. Key decisions regarding risk management policies and oversight will require board approval. Management is tasked with establishing, implementing, and maintaining the risk management framework, with a designated department responsible for overseeing the IT outsourcing activities of various business units.

Detailed risk assessment criteria for outsourced vendors have been specified. Financial institutions must evaluate vendors based on their financial health, services provided, the type and volume of information handled, security measures like encryption and communication methods, incident response capabilities, and IT infrastructure. This information must be updated at least twice a year.

Stricter management standards will apply to "major third parties" that significantly impact the financial company's operations or consumers. The guidelines also outline management procedures for each stage of the outsourcing lifecycle: pre-contract, during the contract, and post-contract. Before signing a contract, companies must verify the vendor's capabilities and information security management through on-site inspections and include clear liability clauses in the contract. During the contract period, performance must be reviewed at least annually, and emergency response and backup management systems must be in place. Upon contract termination, financial companies must ensure the return of all information assets, revoke access rights, and confirm the complete destruction of data.

DistantNews Editorial

Originally published by Hankyoreh in Korean. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.