Third-party risk
An expert-validated risk assessment framework for bank IT supply chain management
The authors propose and validate an expert-based risk assessment framework to manage IT supply chain risks in the banking sector.
Four in five banks use AI to manage op risks
Risk Benchmarking: Cyber risk use cases growing; governance and ROI doubts give some pause
Half of banks use scenarios to set third-party Pillar 2 capital
Risk Benchmarking study finds resilience risk less widely covered than cyber and IT disruption, but more formalised where scenarios exist
Second line seeks to stamp its authority on AI risk
Risk Benchmarking study finds fragmented accountability for AI risk among banks, and most are short of controls to contain it
Everything is connected: Santander’s US CRO shuns siloed thinking
Rise of AI intensifies links between fraud, cyber, third-party and other operational risk categories
Op Risk Benchmarking 2026: explore the data
View interactive charts from Risk.net’s 61-bank study, covering risk appetite breaches, controls, scenario analysis, GRC tech and regulation
How gatecrashers could spoil the tokenisation party
Blockchain can curb settlement risks, but that could come at the expense of new third-party risks
Op Risk Benchmarking: Banks seek a home for AI risk
Risk.net’s 2026 study sees record participation and collective unease, as banks race to incorporate AI into op risk frameworks
Third parties cause third of ICT failures, Dora report shows
First annual report shows IT risk is highly interconnected and international, say EU regulators
Contract negotiation tops tech sovereignty for banks in Asia
Regulatory pressure is rising, but industry still focused on service agreements with third parties
Banks in Asia turn to integrated third-party risk units
Regional and global firms create centres of excellence bridging first and second lines
The do-it-all machine: model risk in the age of generative AI
Banks race to understand risks posed by new breed of multi-purpose bots
Top 10 op risks: AI upends risk taxonomies
AI risk enters annual poll in fifth, but firms split over treating it as a standalone risk or a cross-cutting driver
Top 10 op risks: Resilience put to the test in 2026
Firms reinforce first line, ‘nth’-party diligence, scenario analysis and vendor exit plans
Top 10 operational risks for 2026
Industry shares intel on biggest collective threats, as well as remedies and loss gauges
Top 10 op risks 2026: Cyber stays top, AI risk enters at fifth
Third-party and outsourcing risk climbs to third; fraud and fincrime edge out geopolitical risk
EU clearing houses pressured to diversify cloud vendors
CROs and regulators see tech concentration risk as a barrier to operational resilience
CanDeal looks to simplify third-party risk management
Six-bank vendor due diligence utility seeks international reach
Esma won’t soften regulatory expectations for cloud and AI
CCP supervisory chair signals heightened scrutiny of third-party risk and operational resilience
SGX fortifies its defences to ward off tomorrow’s outages
Exchange operator fosters “breach mentality” to help prepare for business disruption, explains risk chief
New EBA taxonomy could help integrate emerging op risks
Extra loss flags will allow banks to track transversal risks like geopolitics and AI, say experts