| US Interagency Guidance, OCC 2023-17 | Third parties that support critical activities | Critical tier; critical activity recorded at intake |
|---|
| NCUA | Third-party relationships, including CUSOs | Critical or Material tier; CUSO recorded on the vendor |
|---|
| OSFI B-10 (Canada) | High-risk and critical third-party arrangements | Critical tier, with subcontractors mapped |
|---|
| DORA (EU) | ICT services supporting critical or important functions | Critical tier; function recorded for the register of information |
|---|
| EBA Outsourcing Guidelines (EU) | Outsourcing of critical or important functions | Critical tier; outsourcing arrangement flagged |
|---|
| PRA SS2/21 (UK) | Material outsourcing arrangements | Critical or Material tier by your materiality assessment |
|---|
| FCA SYSC 8 (UK) | Outsourcing of critical or important operational functions | Critical tier |
|---|
| RBI (India) | Material outsourcing of IT services | Critical or Material tier by materiality |
|---|
| MAS (Singapore) | Material outsourcing arrangements | Critical or Material tier by materiality |
|---|
| CBUAE (UAE) | Material outsourcing | Critical or Material tier by materiality |
|---|
| APRA CPS 230 (Australia) | Material service providers supporting critical operations | Critical tier; critical operation linked |
|---|
| HIPAA (US) | Business associates and their subcontractors | PHI in scope; tier by data and service criticality |
|---|
| GDPR (EU and UK) | Processors and sub-processors | Personal data in scope; tier by data and service |
|---|
| PCI DSS v4.0 | Third-party service providers (TPSPs) | Account data in scope; tier by service |
|---|
| SOC 1 and SOC 2 reports | Subservice organizations | Mapped as fourth parties, with CUECs tracked |
|---|
| NIST CSF 2.0 | Suppliers prioritized by criticality (GV.SC) | Critical, Material or Low risk tier |
|---|