Financial Firms to Retain Responsibility for Cloud Services Amid IT Risks

By SEOYOUNG LEE Posted : July 29, 2026, 12:03 Updated : July 29, 2026, 12:03

Financial companies will be held accountable for managing risks related to hacking, data breaches, and system failures, even when outsourcing operations to cloud or external IT service providers.

The Financial Supervisory Service announced on July 29 that it has developed 'Guidelines for Managing Third-party IT Risks for Financial Companies' in collaboration with financial associations and central organizations. This initiative comes in response to growing concerns that incidents at outsourced firms could adversely affect financial consumers as the use of cloud and Software as a Service (SaaS) increases.

The guidelines stipulate that the ultimate responsibility for risk management lies with the board of directors of the financial company, even when tasks are delegated to external vendors. Management is required to establish a relevant management system and designate a central management department to oversee the status of outsourcing and the appropriateness of contracts. A three-tier control system will be implemented, linking the central management department, risk management department, and internal audit department.

Financial companies must assess the financial condition of external vendors, the services provided, the types of information processed, encryption methods, and incident response systems, updating this information at least once every six months. Vendors that significantly impact operations or financial consumers will be designated as 'key third parties' and will undergo risk assessments biannually.

Before entering into contracts, companies must verify the service capabilities and information protection systems of vendors through on-site inspections and clearly outline responsibilities in the event of an incident within the contract. During the contract period, they must prepare emergency plans and backup systems to address potential system outages, as well as transition plans for alternative vendors upon contract termination. After the contract ends, access rights must be revoked, and retained information must be completely destroyed.

Industry-specific associations plan to establish best practice standards based on these guidelines, set to take effect after November. However, the actual implementation timeline may vary depending on revisions to internal regulations and organizational adjustments within financial companies.





* This article has been translated by AI.

Copyright ⓒ Aju Press All rights reserved.