An institution signs one contract. Underneath it, unread by anyone at the institution, sit three or four more. The vendor that sells the platform relies on a model provider. The model provider runs on a hyperscaler. The hyperscaler's sub-processors sit in jurisdictions nobody at the institution chose. Regulators across Singapore, Hong Kong, Indonesia, and Malaysia agree, across four distinct instruments, on one central point: none of that chain is treated as moving the institution's own accountability an inch.
Four Markets, One Chain
Singapore has moved fastest to say this outright, and is now saying it twice. The Monetary Authority of Singapore's existing Outsourcing Guidelines already treated vendor risk as the institution's own risk to manage. On 6 March 2026, MAS went further, publishing a Consultation Paper proposing new Guidelines on Third-Party Risk Management that would supersede the Outsourcing Guidelines and extend expectations from formal outsourcing to any third-party service. In parallel, MAS's proposed Guidelines on Artificial Intelligence Risk Management explicitly frame vendor-supplied or cloud-hosted AI and open-source models as third-party risks the institution must govern: reliance on vendors does not reduce the institution's accountability. Two consultations, six months apart, saying the same thing from two different directions.
Hong Kong's framing is older and, in one respect, blunter. The HKMA's Supervisory Policy Manual module SA-2 on outsourcing has required authorised institutions to assess a service provider before engaging it, negotiate specific contractual protections, and maintain ongoing monitoring, since long before AI made the question urgent. What has changed is what sits inside that assessment. The HKMA's 2019 circular on big data analytics and AI already placed accountability for procurement, use, and deployment of AI with an institution's senior management and board, regardless of who built the model. Under SA-2, a vendor-supplied AI system is not a different category of outsourcing. It is outsourcing, and it is assessed, contracted, and monitored the same way.
Indonesia has written the principle into consumer-protection law rather than technology guidance, which makes it harder to argue around. OJK Regulation No. 6/POJK.07/2022 on Consumer and Public Protection in the Financial Services Sector prohibits financial institutions from limiting their accountability for services or failures arising from third parties they work with. That is not a technology rule that happens to cover AI vendors. It is a general prohibition on contracting your way out of responsibility, and it sits alongside OJK Regulation No. 9/POJK.03/2016, which requires banks outsourcing work to secure prior notification, maintain ongoing reporting, include mandatory contractual clauses, and preserve audit rights over whatever the vendor does on their behalf.
Malaysia pairs the same principle with the clearest evidence that it is enforced, not aspirational. Bank Negara Malaysia's Policy Document on Outsourcing requires board-level accountability for outsourcing arrangements, due diligence on any provider's capability and location, contractual terms that preserve the regulator's own access, and a defined exit strategy before the arrangement even begins. The revised Policy Document on Risk Management in Technology treats cloud services within its outsourcing and technology-risk perimeter and requires institutions to retain ownership and control over customer data and critical security material, whoever hosts them. BNM has also shown, through public enforcement action against a Malaysia-licensed institution for relocating outsourced systems without the Bank's prior approval, that "the vendor moved it" is not treated as a defence.
What Nobody Is Tracing
Picture a realistic, composite version of what most regional financial institutions are already running. The institution licenses an AI-enabled platform from a vendor. That vendor's product is built on a foundation model accessed through an API. The API provider hosts its infrastructure on a hyperscaler. The hyperscaler, in the ordinary course of running a global cloud, relies on its own sub-processors, some of them in regions the institution never directly evaluated. Nobody at the institution signed a contract with the model provider, the hyperscaler, or the sub-processor. Nobody at the institution necessarily knows, at any given moment, which of them just changed a model version, moved a workload to a new data centre, or onboarded a new sub-processor of their own.
This is not a claim that vendor chains are inherently unsafe, or that any institution currently running one has failed to manage it. Regulators across all four markets have already built the expectation that institutions manage exactly this. This is an operational visibility problem as much as a regulatory one: the chain itself keeps growing longer, faster than most institutions' outsourcing registers are updated to reflect it.
What This Means for Financial Services Boards
The practical risk does not sit with the vendor named on the primary contract. It sits two or three links further down, where nobody at the institution is looking, because nobody was ever assigned to look there. A thematic review, an outsourcing audit, or a model risk inquiry that asks to see the institution's full AI vendor chain, not just its primary AI vendor, will increasingly find gaps the outsourcing register was never designed to catch: a sub-processor nobody assessed, a model version change nobody was notified of, a data residency assumption that quietly stopped being true.
Most outsourcing reviews still ask whether the primary vendor contract meets the regulator's requirements. Few ask whether anyone has traced the full chain beneath that contract, or who is accountable for noticing when a link two or three steps down changes without anyone upstream being told.
Many institutions will only discover how far the chain actually runs the way these gaps are usually discovered: after an incident, a regulatory inquiry, or an audit that happens to ask about the fourth link rather than the first. When the regulator asks to see the risk assessment for the fourth link in the chain, will the board be looking at a completed register, or an unread contract?
Sources
- MAS, Consultation Paper on Proposed Guidelines on Third-Party Risk Management, issued 6 March 2026, proposing to supersede the existing Guidelines on Outsourcing (Banks) and Guidelines on Outsourcing (Financial Institutions other than Banks).
- MAS, Consultation Paper on Proposed Guidelines on Artificial Intelligence Risk Management, issued 13 November 2025; not yet finalised as of mid-2026.
- HKMA, Supervisory Policy Manual, Module SA-2, Outsourcing; HKMA circular on the use of Big Data Analytics and Artificial Intelligence, issued 5 November 2019.
- OJK, Regulation No. 6/POJK.07/2022 on Consumer and Public Protection in the Financial Services Sector; OJK, Regulation No. 9/POJK.03/2016 on Prudential Principles for Banks Partially Outsourcing Work to Other Parties.
- Bank Negara Malaysia, Policy Document on Outsourcing; Policy Document on Risk Management in Technology (revised, November 2025); public enforcement record disclosing an administrative monetary penalty against a Malaysia-licensed institution, August 2024, for a material outsourcing arrangement change made without the Bank's prior approval.
Editorial Note
This article is a business and organisational commentary, not a legal document. It does not constitute, and must not be relied upon as, legal advice or legal counsel of any kind, and no lawyer-client or advisory relationship is created by reading it.
It is written from a practitioner's vantage point and based on publicly available regulatory instruments and official guidance in English as of mid-2026. It should be read as an architectural diagnosis of organisational design, not as an assessment of any institution's legal position or as commentary on whether any specific vendor arrangement is or is not compliant. Readers and institutions should seek independent legal advice and validate any specific regulatory requirement against the authoritative texts applicable in their jurisdiction before acting on it.