BIS and IOSCO push FMIs to shore up cyber defences

cyber

The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO have jointly issued two new publications addressing resilience risks facing financial market infrastructures (FMIs).

The pair of standard-setting bodies released a cyber resilience toolkit alongside a discussion paper examining how FMIs depend on external technology vendors, with both documents published on the same day.

The toolkit sets out a series of voluntary, non-binding measures intended to help FMIs build stronger cyber resilience frameworks and put into practice the operational resilience elements of the CPMI-IOSCO Principles for Financial Market Infrastructures.

The publication is designed to work alongside, rather than replace, the 2016 CPMI-IOSCO guidance on cyber resilience for FMIs, adding further practical detail for institutions applying that existing framework.

The accompanying discussion paper turns attention to the risks tied to outsourcing, focusing on the challenges that arise when FMIs depend on external providers to deliver services deemed critical to their operations.

Rather than prescribing fixed rules, the paper poses a set of questions to industry stakeholders, inviting feedback on the risks it has identified and on how future engagement between regulators, FMIs and vendors might be shaped.

CPMI functions as the primary international body setting standards for payment, clearing and settlement systems, while IOSCO serves as the global reference point for securities regulation, with both organisations operating under the auspices of standards that member jurisdictions apply to their own financial infrastructure oversight.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.