Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Dco Third Party Risk topic

No spam. Unsubscribe anytime.

Advisory committee backs DCO third‑party safeguards to strengthen operational resilience

Commodity Futures Trading Commission Market Risk Advisory Committee (MRA) · December 11, 2024
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The MRA approved recommendations urging DCOs to implement risk‑based third‑party relationship management programs for critical service providers, aligning CFTC guidance with international standards and urging enhanced due diligence, testing and oversight.

The CFTC Market Risk Advisory Committee on Thursday voted to adopt technology and operations subcommittee recommendations that would require derivatives clearing organizations (DCOs) to institute risk‑based third‑party relationship management for critical vendors.

Presenters urged a principles‑based approach that builds on existing Part 39 system safeguards and international standards such as the Principles for Financial Market Infrastructures and the EU's DORA. The subcommittee recommended that DCOs identify critical third‑party providers, perform enhanced pre‑selection due diligence and onboarding, maintain written policies for ongoing oversight, and require periodic testing and data‑access provisions to assist recovery during multi‑day outages.

Panelists from the Office of the National Cyber Director, Treasury, Intercontinental Exchange, FIA and industry working groups emphasized preparedness, incident response planning, and information sharing as key elements of resilience. Industry speakers described initiatives such as an industry resilience committee and a standardized incident‑response data questionnaire for CCPs and exchanges to expedite recovery and reconnection during outages.

The committee moved and seconded the recommendation; a roll call resulted in 24 yes votes, zero no votes and one abstention. The motion carries and the recommendation will be submitted to the Commission for consideration.

The subcommittee asked the Commission to keep a principles‑based framework that can be adapted across jurisdictions while bringing DCO rules explicitly in line with lessons learned from recent cyber incidents.