Four Supervisors, One Fabric: The Third-Party Register Is Becoming a Regulatory Data Feed - and Most APAC Banks Are Building It Four Times
Executive Summary
Between November 2025 and July 2026, four APAC supervisors moved on the same question, and none of it arrived as a single headline. Bank Negara Malaysia issued a revised Risk Management in Technology policy document on 28 November 2025. The Hong Kong Monetary Authority's deadline for authorized institutions to have become operationally resilient under module OR-2 fell on 31 May 2026; two days earlier it issued Operational Resilience: Sustaining and Uplifting, converting a milestone into a standing obligation to maintain mapping and test periodically (HKMA, 2022; HKMA, 2026). The Monetary Authority of Singapore has three consultations in flight: proposed Guidelines on Third-Party Risk Management and updated Guidelines on Operational Risk Management (both issued 6 March 2026, closed 20 April), plus proposed amendments to eleven Technology Risk Management notices (10 June 2026, closing 31 July). In Australia, CPS 230 has been in force since 1 July 2025 - first Material Service Provider Register submission due 1 October 2025 - with targeted amendments effective 1 July 2026 (APRA, 2026).
Individually, each is a compliance workstream. Together they describe one change: the register has stopped being a document and started being a reporting interface. Four supervisors ask overlapping questions - what is material, what depends on what, who sits behind your provider, what happens when it fails - of the same fabric, on different templates, clocks and taxonomies.
A bank in three or four APAC markets can answer from one canonical dependency model with four jurisdictional projections or maintain four registers built by four teams from four spreadsheets. The first costs an engineering investment once and a mapping exercise per new supervisor. The second costs a programme per jurisdiction, forever, and produces four answers that quietly disagree - the specific failure a supervisor is most likely to find. What follows is the four-layer architecture and a ten-question readiness audit.
Introduction: The Question Behind Every Template
There is a version of this conversation that never leaves the compliance function. A supervisor publishes a template, a team populates it, the board notes it, the file closes until next cycle. That was survivable while the templates were annual, narrative and mostly about contracts.
It is not what is being asked now. Strip the four regimes of local vocabulary and the same four questions sit underneath all of them. Which providers do your critical operations actually depend on? What sits behind those providers - subcontractors, shared platform, single region? How long can each operation be down before the harm is unacceptable, and can you demonstrate the capability to meet that tolerance rather than assert it? And where is the same dependency concentrated across services assessed independently?
None of those is a documentation question. Each is a query against a dependency graph that either exists in machine-readable form or does not.
Industry Context: Four Supervisors, Four Clocks

Australia - APRA CPS 230. In force since 1 July 2025; first Material Service Provider Register submission due 1 October 2025. The amendments finalized 30 April 2026 and effective 1 July 2026 are narrow: limited relief from certain contractual requirements for non-traditional service providers, plus a template flag marking an arrangement exempt (APRA, 2026). The register has been filed once already - which makes the next submission a comparison.
Hong Kong - HKMA SPM module OR-2. Issued 31 May 2022: framework developed, resilience parameters set and interdependency mapping commenced by 31 May 2023; authorized institutions required to have become operationally resilient by 31 May 2026 (HKMA, 2022; KPMG China, 2022). That date has passed, and the 29 May 2026 circular Operational Resilience: Sustaining and Uplifting sets what follows: maintain the framework, refresh mapping as the estate changes, test periodically against severe-but-plausible scenarios, report material disruptions (HKMA, 2026). After a passed deadline comes supervisory testing against what institutions said they had built.
Singapore - MAS, three tracks at once.
- Proposed Guidelines on Third-Party Risk Management (6 March 2026, closed 20 April) would supersede the Outsourcing Guidelines and widen the perimeter from outsourcing to all third-party services, subject to carve-outs including certain government technology services, financial market infrastructures and non-business services with no access to confidential information. Institutions would submit a register of material arrangements to MAS semi-annually and on request, on the template proposed at Annex B, including material subcontractors where possible; monitor concentration risk at service-provider and geographical level, supported by dependency mapping; and hold exit plans covering different plausible termination scenarios, regularly updated and tested. Transition: six months from issuance of the final guidelines (HSF Kramer, 2026; CMS, 2026).
- Updated Guidelines on Operational Risk Management (same date) would supersede the March 2013 guidelines, strengthen change management, and require domestic systemically important banks and insurers to publicly disclose their operational risk management approach, exposures and code of conduct (Rajah & Tann, 2026).
- Proposed amendments to eleven Technology Risk Management notices (10 June 2026, closing 31 July) would clarify that partial or intermittent disruptions count toward the four-hour limit on annual unscheduled downtime for critical systems, effective twelve months after final publication (Allen & Gledhill, 2026b).
None of the three is final. As of 30 July 2026 MAS has published neither final guidelines nor a feedback response on the March papers. Everything above is a proposal - which is why this is the right moment to build the capability, not the wrong moment to wait for the text.
Malaysia - BNM. The revised Risk Management in Technology policy document was issued 28 November 2025, strengthening technology and cyber supply-chain expectations, including due diligence extending to subcontractors (Bank Negara Malaysia, 2025; Allen & Gledhill, 2026a). PwC Malaysia's reading of it flags a stand-in processing capability for least-substitutable services by 30 September 2027 (PwC Malaysia, 2025) - a planning assumption to confirm against the policy text, not settled wording. In March 2026 BNM also issued the Policy Document on Technology Requirements for Payment Services Regulatees (Bank Negara Malaysia, 2026): the perimeter is widening beyond banks.
Two observations. The direction of travel is uniform - from outsourcing to all third parties, from contracts to dependencies, from annual narrative to periodic structured submission, from third party to fourth party. The detail is deliberately local - different materiality tests, templates, cadence and vocabulary for the same concept. That combination is exactly the condition where one canonical model with jurisdictional projections beats parallel programmes, and exactly the condition under which most banks nonetheless run parallel programmes.
Current Challenges: Why Four Registers Is the Default Outcome
Nobody chooses four registers. It is what happens when three ordinary organizational facts collide.
The obligation arrives in-country. Each supervisor engages a local entity, risk function and board - and nothing in that structure prompts anyone to ask whether the Singapore submission and the Australian register describe the same platform.
The taxonomies genuinely differ. APRA's materiality test, MAS's proposed materiality assessment and BNM's technology-risk framing classify the same provider differently, and a group model that flattens them is wrong in every jurisdiction. The answer is not one shared spreadsheet; it is one shared model with jurisdiction-specific classification rules applied on the way out.
The fourth-party layer is where the model breaks. Both the MAS proposals and BNM's revised RMiT push into material subcontractors, and almost no bank can enumerate its fourth parties from a system of record - that information lives in supplier questionnaires, contract annexes and the memory of a vendor manager. It is the largest single gap between what the 2026 regimes ask for and what most institutions can produce.
Above all: concentration risk is invisible at the level where registers are assembled. Ask a business unit whether it is over-concentrated and it will say no, correctly, from where it sits. Concentration is a property of the whole graph - the same region, identity provider, messaging network or delivery center appearing behind eleven independently assessed services. Gartner expects worldwide sovereign cloud infrastructure-as-a-service spending to reach approximately US$80 billion in 2026, up 35.6 per cent, with mature Asia/Pacific markets growing fastest at roughly 87 per cent this year (Gartner, 2026). But sovereign regions solve jurisdiction, not concentration: a workload moved in-country while still depending on one provider's global control plane has a new residency answer and an unchanged concentration answer. As the BIS Financial Stability Institute observed in 2022, "four big techs control close to two thirds of the global market for cloud computing", and with no readily available substitutes "a disruption in one of these big techs could have systemic implications for the financial system" (Bank for International Settlements, 2022). The measurement is four years old; the structural point is not.
Key Trends: What 2026 Signals About 2027
The register becomes a periodic structured submission. MAS's proposed semi-annual filing is the leading indicator; APRA's register has been filed once already. Once a supervisor holds comparable structured data across an industry, it can run sector-level concentration analysis no single institution can run for itself - and will ask about what it finds.
Attention shifts from framework to evidence. With HKMA's milestone passed and its Sustaining and Uplifting expectations live, and CPS 230 one cycle in, the 2026-27 question is not "do you have a framework" but "show me the last test, the last incident, and the reconciliation between stated tolerance and measured recovery". Proposed public disclosure of operational risk approach and exposures by domestic systemically important banks and insurers pushes the same way: numbers only defensible internally become numbers defensible in public.
Tolerance definitions are tightening faster than architectures. Counting partial and intermittent disruption toward the four-hour annual downtime limit is a small drafting change with a large consequence: degradation would consume the same budget as outage, favoring designs that fail in isolated components over designs that stay nominally "up" while running slow.
Strategic Analysis: One Model, Four Projections
The architecture that satisfies four supervisors from one source has four layers, and the sequence matters more than the tooling.

Layer 1 - A canonical service inventory. One list of services with stable identifiers, from which every jurisdictional report is generated. Not a taxonomy invented for the register, and not the configuration management database as-is: it must be the same objects the delivery organization deploys, or it drifts within a quarter. Test: does a register entry resolve to something a platform engineer can point at in production?
Layer 2 - A dependency graph, including fourth parties. Edges from service to provider, provider to subcontractor, service to region, service to shared component - populated from live signals (service maps derived from traffic, deployment and identity metadata), with manual entry reserved for what cannot be observed, chiefly commercial subcontracting. Test: is "everything that depends on provider X" a query or a project?
Layer 3 - Criticality and tolerance, per jurisdiction. The same node carries several classifications: material under CPS 230, material under the MAS proposals, in scope as an OR-2 critical operation, in scope under RMiT. Local rules live here, and this is where group models fail by picking one definition and calling it global. Tolerances attach here too, each paired with an observability signal that would demonstrate the capability under test rather than assert it.
Layer 4 - A projection and reporting layer. Jurisdictional views generated from Layers 1-3: the APRA register with exempt flags where they genuinely apply; a MAS semi-annual submission; OR-2 evidence packs; RMiT-aligned status. Generated, versioned and diffable - so the change between two submissions is itself a reviewable artefact.
The economics are plain. Four registers cost roughly four times one, every cycle, with reconciliation risk rising as the count grows. One model with four projections front-loads the engineering and makes the marginal cost of the fifth supervisor a mapping exercise - and that marginal cost is the number a board should ask about.
One caveat against our own argument: a single-jurisdiction institution with a contained estate and a stable provider set does not need this, and the layered model would be over-engineering. The threshold is roughly two or more supervisors, or one supervisor plus a live modernization programme that changes the graph faster than an annual review can track. Below that line, judgement beats infrastructure.
Real-World Examples
The second jurisdiction as a mapping exercise. A multi-jurisdiction banking group built its dependency model for the Australian entity ahead of CPS 230, deriving service maps from live traffic rather than interviews. When the MAS papers landed in March 2026 with a different materiality test and template, the Singapore work was classification and projection against an existing graph, not new discovery. The first jurisdiction cost a build; the second cost a sprint.
Fourth-party discovery as data acquisition. A bank facing subcontractor expectations across multiple jurisdictions amended its standard supplier agreement to require subcontractor disclosure and change notification, and pointed those disclosures at the dependency graph rather than a shared drive. Coverage of material providers moved from partial and stale to substantially complete and refreshed on notification - because the duty to keep it current sat with the party holding the information.
The reconciliation nobody wants to be asked for. A bank operating across Australia and Singapore held an Australian register and a Singapore outsourcing schedule prepared in different cycles by different teams. A number of providers appeared in one submission and not the other; some were classified as material in one jurisdiction and non-material in the other on facts that had not changed. Nobody had done anything wrong - the artefacts came from different snapshots of a moving estate. That is what a supervisor comparing two group submissions notices, and what a single canonical model makes impossible by construction.
Actionable Recommendations: The Ten-Question Register Readiness Audit
Score each 0 (no), 1 (partially), 2 (yes, demonstrable).
Inventory - 1. Is there exactly one canonical service inventory that every jurisdictional report is generated from? 2. Does each register entry resolve to a service identifier an engineer can point at in production?
Dependencies - 3. Can you answer "everything that depends on provider X" as a query, in minutes, without convening a working group? 4. Is any part of the graph populated from live signals rather than interviews? 5. Do you hold subcontractor information for material providers in a system of record, refreshed on notification rather than at renewal?
Criticality and tolerance - 6. Can one provider carry different materiality classifications for different supervisors without separate registers? 7. Does every stated tolerance have a paired observability signal that would demonstrate the capability under test? 8. Can you produce concentration exposure across the whole graph - same region, provider, component - rather than per business unit?
Projection - 9. Are jurisdictional submissions generated from the model, versioned and diffable between periods? 10. If a fifth supervisor published a template tomorrow, is your answer a mapping exercise or a programme?
Interpretation. 16-20: ahead of most institutions in the region - spend the next cycle on evidence quality, not structure. 8-15: the model exists in fragments and reconciliation is your live risk. 0-7: you are on the four-registers path, and the curve steepens with each obligation; the first move is not a governance forum but one canonical inventory and one graph.
Two moves worth board time this quarter: name a single accountable owner for the dependency model, distinct from the owners of each jurisdictional submission; and put subcontractor disclosure and change-notification clauses into the standard supplier agreement now, ahead of renewals rather than at them.
The sourceCode Perspective: Reporting Is an Engineering Product
We build these layers for APAC banks, so the bias is declared: we think this is an engineering problem mis-filed as a compliance problem. What we observe consistently is that institutions producing fast, credible, reconcilable regulatory answers did not buy a governance platform and populate it. They treated the dependency model as a product - owner, schema, live data sources, tests, and consumers who include both a regulator and a platform team. The register is then a view over that product, not a parallel artefact. It is also why observability instrumented before a migration matters so much: the signals that tell an engineer a service is healthy are the signals that demonstrate a tolerance to a supervisor.
The caution: this pays where the estate is genuinely moving or multi-jurisdictional. Where it is both - most groups modernizing across Australia and Southeast Asia in 2026 - the parallel-register path is a recurring cost that grows with every template published.
Conclusion: Build It Once
HKMA's deadline has passed and its expectation is now continuous. CPS 230 is in force and its register has been filed once. MAS has three consultations, none final, with six- and twelve-month transitions on the other side. BNM has revised its technology policy for banks and extended requirements to payment services regulatees. None of these regimes is asking for a document. All four ask the same thing in different words: demonstrate that you know what your critical operations depend on, and that you can survive those dependencies failing.
Institutions that build one model and project it per jurisdiction will spend the next two years improving evidence. Institutions that build a register per supervisor will spend those years reconciling artefacts that were never generated from the same snapshot - and explaining the differences to people whose job is to notice them.
The 2027 regulatory calendar is not published yet. That is exactly why the marginal cost of the next template is the number worth knowing today.
Score your own register in ten minutes. The full Register Readiness Audit - the ten questions with scoring guidance, the four-layer reference architecture, and a jurisdictional classification matrix mapping APRA, HKMA, MAS and BNM requirements onto one data model - sits inside the APAC Core Banking Modernization Playbook 2026, alongside the CPS 230 addendum.
Read it here: APAC Core Banking Modernization Playbook 2026 →
If you would rather have a second read on your own dependency model than a PDF, sourceCode's running complimentary 30-minute Architecture Reviews through August.
Frequently Asked Questions
What is a third-party arrangement under the MAS proposals? Under the Guidelines on Third-Party Risk Management proposed by MAS on 6 March 2026, a third-party arrangement is any arrangement under which a financial institution obtains a service from an external party - a wider perimeter than the outsourcing arrangements covered by the guidelines it would supersede, subject to stated carve-outs, with material arrangements subject to register, monitoring, concentration-risk and exit-planning expectations. The guidelines remain at consultation stage as of 30 July 2026.
What would MAS require institutions to submit, and how often? The proposals would require financial institutions to maintain a record of their third-party arrangements and to submit a register of material third-party arrangements - including material subcontractors where possible - to MAS semi-annually and upon request, using the template proposed at Annex B of the consultation paper, with a six-month transition from issuance of the final guidelines.
When did HKMA require banks to be operationally resilient? Under HKMA Supervisory Policy Manual module OR-2, issued 31 May 2022, authorized institutions were required to have become operationally resilient by 31 May 2026, having developed their framework, set resilience parameters and commenced interdependency mapping by 31 May 2023. The circular of 29 May 2026, Operational Resilience: Sustaining and Uplifting, sets the continuing expectation beyond that date.
What is a material subcontractor, and why does it matter in 2026? A material subcontractor is a party engaged by your service provider whose failure would materially affect a service you depend on; both the MAS proposals and BNM's revised RMiT extend risk-management expectations into this fourth-party layer, which is where most APAC institutions currently lack a system of record.
What does BNM's revised RMiT add, and by when? The revised Risk Management in Technology policy document issued 28 November 2025 strengthens technology and cyber supply-chain risk expectations, including due diligence extending to subcontractors. PwC Malaysia's summary also flags a stand-in processing capability for least-substitutable services by 30 September 2027, plus near-term work on service-level agreement clauses and software-bill-of-materials tooling; institutions should confirm those dates against the policy document itself. Separately, BNM issued the Policy Document on Technology Requirements for Payment Services Regulatees on 12 March 2026 (Bank Negara Malaysia, 2026), extending proportionate technology risk requirements to approved e-money issuers, registered merchant acquirers and money services businesses.
What is a register projection? A register projection is a jurisdiction-specific regulatory report generated from a single canonical dependency model rather than maintained as a standalone artefact - so that APRA's Material Service Provider Register, a MAS semi-annual submission and OR-2 evidence all derive from the same snapshot of the same estate.
Does moving to a sovereign cloud region reduce concentration risk? No. A sovereign or in-country region addresses data residency and jurisdictional control; concentration risk is a property of how many otherwise-unrelated critical operations depend on the same provider, control plane, region or platform component, and it can remain unchanged - or increase - after a sovereign migration.
What is stand-in processing? Stand-in processing is the capability to continue authorizing and processing a defined subset of transactions when a primary system or provider is unavailable, using a simplified rule set - the capability flagged for least-substitutable services in Malaysia by 30 September 2027 in PwC Malaysia's reading of BNM's revised RMiT policy document.
Do partial outages count against MAS's four-hour downtime limit for critical systems? Under amendments to eleven Technology Risk Management notices proposed by MAS on 10 June 2026 (consultation closing 31 July 2026), partial or intermittent disruptions would count toward the four-hour limit on annual unscheduled downtime for critical systems, with requirements effective twelve months after final publication.
References
Allen & Gledhill, 2026a. Bank Negara Malaysia revises policy document on Risk Management in Technology. Available at: https://www.allenandgledhill.com/perspectives/publications/bulletins-malaysia/2026/bank-negara-malaysia-revises-policy-document-on-risk-management-in-technology/ [Accessed 30 July 2026].
Allen & Gledhill, 2026b. MAS consults on proposed amendments to Notices on Technology Risk Management. Available at: https://www.allenandgledhill.com/sg/publication/articles/33109/sgkh-mas-consults-on-proposed-amendments-to-notices-on-technology-risk-management [Accessed 30 July 2026].
Australian Prudential Regulation Authority (APRA), 2026. APRA finalises targeted amendments to CPS 230 Operational Risk Management, 30 April. Available at: https://www.apra.gov.au/news-and-publications/apra-finalises-targeted-amendments-to-cps-230-operational-risk-management [Accessed 30 July 2026].
Bank for International Settlements (Financial Stability Institute), 2022. Big tech interdependencies - a key policy blind spot, FSI Insights No. 44, 5 July. Available at: https://www.bis.org/fsi/publ/insights44.pdf [Accessed 30 July 2026].
Bank Negara Malaysia, 2025. Risk Management in Technology (RMiT), policy document, 28 November. Available at: https://www.bnm.gov.my/documents/20124/938039/pd-rmit-nov25.pdf [Accessed 30 July 2026].
Bank Negara Malaysia, 2026. Technology Requirements for Payment Services Regulatees, policy document, 12 March. Available at: https://www.bnm.gov.my/documents/20124/943361/pd-tecreq-psr-mar2026.pdf [Accessed 7 August 2026].
CMS, 2026. MAS consultations on third party risk management and updated operational risk management guidelines. Available at: https://cms.law/en/sgp/legal-updates/mas-consultations-on-third-party-risk-management-updated-operational-risk-management-guidelines [Accessed 30 July 2026].
Financial Stability Board, 2023. Enhancing Third-Party Risk Management and Oversight: A Toolkit for Financial Institutions and Financial Authorities, December. Available at: https://www.fsb.org/2023/12/final-report-on-enhancing-third-party-risk-management-and-oversight-a-toolkit-for-financial-institutions-and-financial-authorities/ [Accessed 30 July 2026].
Gartner, 2026. Gartner Says Worldwide Sovereign Cloud IaaS Spending Will Total $80 Billion in 2026, press release, 9 February (US$80bn in 2026, +35.6 per cent year on year; mature Asia/Pacific forecast to grow approximately 87 per cent in 2026). Available at: https://www.gartner.com/en/newsroom/press-releases/2026-02-09-gartner-says-worldwide-sovereign-cloud-iaas-spending-will-total-us-dollars-80-billion-in-2026 [Accessed 30 July 2026].
Herbert Smith Freehills Kramer (HSF Kramer), 2026. Extending the regulatory perimeter beyond outsourcing: MAS proposed third-party risk management guidelines. Available at: https://www.hsfkramer.com/notes/fsrandcorpcrime/2026-posts/extending-the-regulatory-perimeter-beyond-outsourcing-mas-proposed-third-party-risk [Accessed 30 July 2026].
Hong Kong Monetary Authority (HKMA), 2022. New module OR-2 on "Operational Resilience" and revised module TM-G-2, circular, 31 May. Available at: https://brdr.hkma.gov.hk/eng/doc-ldg/docId/getPdf/20220531-1-EN/20220531-1-EN.pdf [Accessed 30 July 2026].
Hong Kong Monetary Authority (HKMA), 2026. Operational Resilience: Sustaining and Uplifting, circular, 29 May. Available at: https://brdr.hkma.gov.hk/eng/doc-ldg/docId/getPdf/20260529-5-EN/20260529-5-EN.pdf [Accessed 30 July 2026].
KPMG China, 2022. Operational resilience: HKMA's new standard issued, June. Available at: https://assets.kpmg.com/content/dam/kpmg/cn/pdf/en/2022/06/operational-resilience-hkma-new-standard-issued.pdf [Accessed 30 July 2026].
Monetary Authority of Singapore (MAS), 2026a. Consultation Paper on Proposed Guidelines on Third-Party Risk Management, 6 March. Available at: https://www.mas.gov.sg/regulation/third-party-risk-management [Accessed 30 July 2026].
Monetary Authority of Singapore (MAS), 2026b. Consultation Paper on Updated Guidelines on Operational Risk Management, 6 March. Available at: https://www.mas.gov.sg/publications/consultations/2026/consultation-paper-on-updated-guidelines-on-operational-risk-management [Accessed 30 July 2026].
PwC Malaysia, 2025. 2025 updates: BNM Risk Management in Technology (RMiT), December. Available at: https://www.pwc.com/my/en/assets/pdf/2025-updates-bnm-rmit-risk-management-in-technology.pdf [Accessed 30 July 2026].
Rajah & Tann Asia, 2026. MAS consults on updated Guidelines on Operational Risk Management. Available at: https://www.rajahtannasia.com/viewpoints/mas-consults-on-updated-guidelines-on-operational-risk-management/ [Accessed 30 July 2026].