A conversation with a bank’s head of operational resilience and why third‑party risk is the missing piece
Last week, I sat down with the head of operational resilience at a major bank. Over tea, he shared a frustration that I have heard from many financial institutions.
“Imran, we have all the SAMA BCM policies in place. We test our disaster recovery twice a year. The reports look good. But I’ll be honest when a real ransomware attack hits, or when one of our critical vendors fails, I’m not sure our recovery plan will hold together.”
He explained the real problem. His bank runs critical functions across hundreds of x86 servers, but that is only part of the story. The bank also relies on dozens of third‑party vendors for cloud services, payment processing, and model development. Each vendor introduces its own failure points, security gaps, and compliance risks.
“SAMA’s BCM framework and Cybersecurity Framework both require us to manage third‑party risk,” he said. “But with this sprawling vendor ecosystem, how do I prove that my vendors can meet my recovery objectives? How do I ensure their security gaps don’t become my gaps?”
I leaned in. “What if I told you there is a platform that gives you hardware‑enforced proof not just promises for every single one of those problems, including third‑party oversight?”
The Third‑Party Risk Blind Spot
SAMA has made third‑party risk management (TPRM) a non‑negotiable pillar of its regulatory framework. The SAMA Cybersecurity Framework (Section 3.4) explicitly mandates that member organizations manage third‑party cyber security across contracts, due diligence, and ongoing monitoring. The SAMA Outsourcing Rules govern the entire vendor engagement process, requiring a thorough review of the vendor’s operational, financial, legal, and reputational risks plus a robust business continuity plan, especially for overseas vendors, where enhanced due diligence is required.
Research
A 2025 Dun & Bradstreet survey found that 91% of financial services firms experienced negative effects from third‑party relationships, with average losses exceeding $700,000. A separate Ncontracts 2025 survey found that over one‑third of large banks manage more than 1,000 vendors, creating “vendor sprawl” that makes TPRM nearly impossible to manage manually.
Yet, despite the rising risks, only 8% of financial institutions feel fully compliant with DORA’s two toughest requirements: digital operational resilience testing and ICT third‑party risk management. In the UK, the PRA’s Operational Resilience framework and the Critical Third Party (CTP) regime impose parallel obligations.
The Turning Point
I pulled out a napkin and drew a quick comparison bringing third‑party risk directly into the operational resilience picture.
My friend stared at the napkin. “So you’re telling me that by consolidating onto one platform, I reduce my third‑party risk exposure and the platform gives me immutable proof that I can use for SAMA vendor audits?”
“Exactly,” I said. “And that’s a message your entire C‑suite needs to hear.”
The Expertise You Need to Master Third‑Party Risk
He looked at me. “What do my people actually need to know to make sense of this?”
I shared a quick competency checklist that every TPRM team in a bank should have:
“Most banks don’t have that mix,” I added. “That’s where you come in as a consultant.”
The Bottom Line for Banks and Consultants
SAMA demands that financial institutions manage third‑party risk as a first‑class discipline from risk assessment and contract clauses down to oversight of subcontractors (fourth parties). IBM LinuxONE doesn’t replace your vendor management program; it drastically reduces the number of vendors you need to manage, while the hardware‑enforced audit trails give you the proof regulators require.
-
Fewer vendors, simpler due diligence consolidation shrinks your third‑party attack surface.
-
Hardware‑enforced, immutable audit trails for every recovery action, directly mappable to SAMA’s vendor compliance expectations.
-
Secure Service Containers lock out vendor staff from your most sensitive recovery data.
For the consultant in the room, this is a service to sell a resilience gap analysis that includes third‑party dependencies. For the bank, this is a foundation that finally makes operational resilience provable, not just planned.
If you want to stop hoping that your vendors won’t fail and start proving that you can recover the platform exists. The question is how soon you can start the conversation.
👇 Read the full LinuxONE series for more technical insights:
🔗 https://community.ibm.com/community/user/blogs/imran-jalil
What is the single biggest third‑party risk gap in your financial institution today? Let me know in the comments.
#SAMA #BCM #OperationalResilience #ThirdPartyRisk #TPRM #DORA #IBMZ #LinuxONE #SaudiArabia #FinancialInstitutions #RiskManagement #BusinessContinuity