Skip to content

Global payments intelligence

Updated Sep 12, 2026 · 21:19 UTC

Now tracking Nacha’s September 18 Rules Put IAT Classification and ACH Posting Under Review
Payments intelligence
Payment Infrastructure

CPMI-IOSCO Flag Vendor Lock-In and Cloud Risk at Critical Payment Systems

Global standard setters say critical payment and market infrastructures face growing cyber and operational risk from concentrated technology providers, opaque supply chains and difficult exits.

Global payments and securities standard setters have put technology-provider concentration, vendor lock-in and opaque supply chains at the center of a new review of cyber resilience at critical financial infrastructure.

The Committee on Payments and Market Infrastructures and the International Organization of Securities Commissions published two consultative documents on September 8: a practical cyber-resilience toolkit and a discussion paper on financial market infrastructures’ reliance on third-party service providers. The work covers systemically important payment systems as well as central securities depositories, securities settlement systems, central counterparties and trade repositories.

The documents do not report a specific attack, outage or breach, and they do not establish new binding requirements. They instead identify structural control problems that can magnify disruption at infrastructure through which payments and financial-market transactions are cleared, settled or recorded.

Concentration can turn a supplier failure into infrastructure risk

CPMI-IOSCO says financial market infrastructures are using more third-party services, including for critical operations. A survey of member authorities found that the increase has been particularly visible in cloud computing and other information-technology services. Those authorities expect reliance to grow further over the next three to six years.

The accountability problem is not removed by outsourcing. The discussion paper says jurisdictions generally noted or implied that an infrastructure operator retains ultimate responsibility for risks arising from activities performed by a third party. Yet an operator may depend on a single supplier or a small provider group, while the wider market may share the same providers.

That creates two layers of concentration risk. At the operator level, limited substitutes can produce lock-in and leave critical operations exposed to one supplier’s disruption. At the system level, a failure at a provider used by several infrastructures can have broader consequences. CPMI-IOSCO says those concerns could intensify as operators move further into cloud computing and technologies such as artificial intelligence, where major suppliers are limited.

The paper also points to an imbalance in bargaining power. A concentrated provider market can leave infrastructure operators with fewer choices and less ability to negotiate contract terms needed for effective risk management. High switching costs and complex architectures can make an exit impracticable precisely when a stressed operator most needs one.

Opaque supply chains weaken oversight and recovery planning

Direct suppliers are only part of the dependency map. Most surveyed jurisdictions require information about first-level providers, according to the paper, but only some require data on subcontractors farther down the supply chain. CPMI-IOSCO says complex and opaque supply chains can obstruct the identification of critical dependencies and hinder resilience planning.

The paper says cybersecurity and data protection were the operational risks cited most often by participants in its infrastructure roundtable and by member authorities. A cyber incident can begin within an operator or at an external provider, while a supply-chain attack can exploit a weaker vendor connected to the target. Cross-border delivery and long subcontracting chains make those exposures harder to monitor.

The standard setters also highlight an unresolved ecosystem issue: just under half of the financial market infrastructures responding to their survey said they explicitly considered their own role in transmitting risk to the wider ecosystem as part of risk assessment and management. Earlier CPMI-IOSCO implementation reviews had identified concern about insufficient testing coordination with critical providers and, in some cases, limited oversight of outsourced services.

For payment-system operators, processors and settlement providers, the practical question is therefore broader than whether a named cloud or software vendor meets a security checklist. Operators need to know which critical services depend on the same provider, which subcontractors support them, what access and audit rights contracts provide, whether alternatives can be activated under stress, and how a disruption could reach participants, linked systems, settlement banks and liquidity providers.

The toolkit shifts attention from plans to tested recovery

The accompanying 69-page toolkit gives operators voluntary, non-binding tools for governance, extreme-but-plausible scenarios, response and recovery, and cyber testing. It supplements rather than replaces the existing Principles for Financial Market Infrastructures and CPMI-IOSCO’s 2016 cyber guidance.

One section focuses on identifying the critical operations and information assets needed to resume operations within two hours after a disruptive event. It also addresses safe disconnection and reconnection of affected participants, service providers and linked infrastructures, as well as the infrastructure and data-resilience measures needed for a safe recovery.

Other sections cover governance benchmarking, scenario design, testing before and after significant system changes, red-team exercises and lessons from testing. The emphasis matters because a recovery objective is not evidence that an operator can meet it when data integrity is uncertain, a shared supplier is unavailable or connected firms must be isolated and later reconnected.

These are consultative materials, not an enforcement finding against any named operator or technology company. Their significance lies in the control questions they put before a highly interconnected sector: who can see the full dependency chain, who can compel a critical vendor to provide information, and whether an exit or recovery strategy remains workable during a real incident.

CPMI-IOSCO requested comments from infrastructures, providers and other stakeholders by December 1, 2026. Responses are intended to inform whether the standard setters should engage further on third-party risk and whether the identified challenges are complete.