According to South Korea's Financial Supervisory Service (FSC), on July 29, financial institutions' boards of directors and management must assume final responsibility for cybersecurity incidents and data breaches occurring at external IT service providers they contract with.
The FSC established the guideline to manage third-party IT risks more effectively as financial firms increasingly outsource IT operations due to digitalization. Under the framework, financial companies must establish a three-tier control system comprising an oversight department, risk management department, and internal audit department. The board will oversee third-party IT risk management policies, while management must build and maintain the risk management system and conduct ongoing assessments of outsourced IT contracts and service provider financial stability.