News & Analysis as of

Third-Party Service Provider Regulatory Oversight

Bass, Berry & Sims PLC

From 1999 to Prime Time: OIG Revamps Medicare Advantage Guidance for Today’s—and Tomorrow’s—Evolving Market

On February 3, the U.S. Department of Health and Human Services Office of Inspector General (OIG) issued new Medicare Advantage Industry Segment-Specific Compliance Program Guidance (MA ICPG) for the MA industry and...more

Foley & Lardner LLP

Medicare Advantage: New OIG Compliance Guidance Has Implications for Providers

Foley & Lardner LLP on

On February 3, 2026, the U.S. Department of Health & Human Services, Office of Inspector General (OIG), published the long-awaited Medicare Advantage Industry Segment-Specific Compliance Program Guidance (Medicare Advantage...more

Latham & Watkins LLP

UK Parliamentary Committee Publishes Report on AI in Financial Services

Latham & Watkins LLP on

The Committee believes that the financial services regulators are not doing enough to manage the risks presented by AI....more

Mayer Brown

EU–UK Financial Regulators Collaborate on Oversight of Critical ICT Third-Party Providers

Mayer Brown on

Certain large scale ICT companies (known as critical ICT third party providers, "CTPPs") which provide critical cloud storage, technology and data services to banks and other financial institutions play an increasingly...more

Carlton Fields

NAIC’s Third-Party Data and Model Vendors Regulatory Framework Strikes Some Sour Notes

Carlton Fields on

The National Association of Insurance Commissioners’ (NAIC) Third-Party Data and Models (H) Working Group issued a preview of its breakout single: a proposed risk-based regulatory framework for third-party data and model...more

Skadden, Arps, Slate, Meagher & Flom LLP

Ransomware: What You Need to Know as Attacks, Regulation and Enforcement Increase

Ransomware attacks continue to evolve in sophistication, disrupting operations and commanding the urgent attention of regulators, law enforcement and government agencies....more

Katten Muchin Rosenman LLP

ESAs and UK Regulators Sign Memorandum of Understanding on Cross Border Oversight of Critical ICT Providers under DORA

The European Supervisory Authorities (ESAs) and the UK’s Bank of England, Prudential Regulation Authority and Financial Conduct Authority (together, the UK Regulators) have signed a Memorandum of Understanding (MoU) to...more

A&O Shearman

ESAs And UK Regulators Sign MoU On Oversight Of Critical ICT Third-Party Service Providers Under DORA

A&O Shearman on

The European Supervisory Authorities (comprising the European Securities and Markets Authority, the European Insurance and Occupational Pensions Authority and the European Banking Authority) have entered into a Memorandum of...more

Ropes & Gray LLP

NYDFS Regulated Entities Face Stronger Cybersecurity Regulations

Ropes & Gray LLP on

The New York Department of Financial Services (“NYDFS”) implemented the final phases of amendments to its NYDFS Cybersecurity Regulation (23 NYCRR Part 500) in May and November....more

Cooley LLP

The Most Common AI “Risk Factor” Categories

Cooley LLP on

With the news that over 70% of S&P 500 companies provide some sort of AI-related risk factors in their SEC disclosures, it’s a good time to review the type of risk factors that you might want to consider – of course,...more

Troutman Pepper Locke

NCUA Issues Updated AI Resource Hub

Troutman Pepper Locke on

On December 22, the National Credit Union Administration (NCUA) updated its Artificial Intelligence (AI) resource page to consolidate key technical and policy references for federally insured credit unions. The page sits...more

Ropes & Gray LLP

On the Tenth Day of Data… Looking Back at 2025 and Ahead to NYDFS Enforcement Priorities in 2026

Ropes & Gray LLP on

While 2025 may have brought questions about the level of enforcement we would see from federal regulators, there was no question that state regulators would continue to be active, especially in the financial privacy space....more

A&O Shearman

BCBS principles for the sound management of third-party risk

A&O Shearman on

The Basel Committee on Banking Supervision (BCBS) has published its principles for the sound management of third‑party risk, replacing the 2005 Joint Forum outsourcing paper and establishing a common baseline for banks and...more

Troutman Pepper Locke

Key Takeaways from FINRA’s 2026 Annual Regulatory Oversight Report

Troutman Pepper Locke on

The Financial Industry Regulatory Authority’s (FINRA) 2026 Annual Regulatory Oversight Report is the most current and comprehensive statement of FINRA’s priorities and expectations for member firms. It does not create new...more

McGuireWoods LLP

FINRA’s 2026 Annual Regulatory Oversight Report: Same Priorities, New Focus on AI and Cybersecurity

McGuireWoods LLP on

SERC’ling Up is your resource for staying ahead in today’s fast-evolving financial landscape. This newsletter delivers perspectives on the latest enforcement trends, regulatory updates and high-stakes developments affecting...more

Hudson Cook, LLP

OCC Requests Feedback on Community Banks' Engagement with Core and Essential Service Providers

Hudson Cook, LLP on

On November 28, 2025, the Office of the Comptroller of the Currency ("OCC") issued a request for information ("RFI") on community banks' engagement with their core service providers and other essential third-party service...more

Jones Day

NY Department of Financial Services Signals Increased Scrutiny of Third-Party Technology Risk Management

Jones Day on

On October 21, 2025, the New York Department of Financial Services ("NYDFS") sent a letter to the executives and information security personnel at covered entities with new guidance for managing technology and data risks...more

Mitratech Holdings, Inc

Third‑Party AI: The Blind Spot in Governance

Ask any board if AI is on the agenda, and the answer is yes. Ask how confident they feel about their vendors’ use of AI, and the answer is less clear....more

DLA Piper

Singapore: Key Amendments to the Cybersecurity Act Now in Force

DLA Piper on

Since the enactment of Singapore’s Cybersecurity Act 2018 (Cybersecurity Act), Singapore’s digital economy has grown rapidly, and cyber threats have evolved at a remarkable pace. To address this shifting landscape, the...more

A&O Shearman

ESAs publish official list of designated critical CTPPs under DORA

A&O Shearman on

The European Supervisory Authorities, referred to as ESAs (comprising the European Banking Authority, European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority) have published...more

Katten Muchin Rosenman LLP

ESAs Publish List of Critical ICT Third Party Service Providers under EU DORA

On 18 November 2025, the European Supervisory Authorities (ESAs) published the first list of designated critical information and communication technology (ICT) third party service providers (CTPPs) under the EU Digital...more

Ropes & Gray LLP

Initial Guidance on Responding to the SitusAMC Data Breach

Ropes & Gray LLP on

Over the last weekend, major media reported that a key financial services provider, SitusAMC, suffered a substantial data security incident. This Alert summarizes what we know so far, the possible legal implications, and some...more

Conyers

The Basics of Listing a Cayman Segregated Portfolio on the Cayman Islands Stock Exchange

Conyers on

Segregated portfolio companies (collectively, “SPCs” and individually, an “SPC”) are commonly used in the Cayman Islands as fund vehicles for umbrella funds....more

DLA Piper

DORA’s Critical ICT Provider List Published – A New Milestone for Digital Resilience

DLA Piper on

In a significant stride toward strengthening digital stability in Europe’s financial sector, the European Supervisory Authorities (EBA, EIOPA, and ESMA) have, today, published the list of critical ICT third‑party service...more

Troutman Pepper Locke

FERC Staff Audit Report Identifies CIP Standard Compliance Risks in FY2025

Troutman Pepper Locke on

On October 20, 2025, FERC Staff issued a report outlining areas of risk to the reliability of the electric grid based on non-public Critical Infrastructure Protection (CIP) Audits of U.S. based North American Electric...more

59 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide