When financial institutions evaluate technology providers, the scorecard is familiar: functionality, compliance coverage, integration effort, and total cost of ownership. Often further down the list sits a question that deserves to be near the top: what happens to this vendor, and to us, when something goes wrong?
For central banks and financial institutions, this is no longer a hypothetical consideration. Systemically important payment, clearing and settlement infrastructures support services whose disruption can extend beyond one organization to participating institutions, businesses and end users. An institution can build exemplary internal resilience and still inherit fragility from a critical third-party dependency.
Resilience Is Now a Regulatory Expectation, Not a Differentiator
Supervisory frameworks are increasingly explicit about the importance of third-party resilience. The Basel Committee's Principles for Operational Resilience direct institutions to manage dependencies on third parties with the same rigor they apply to internal operations.
In the European Union, the Digital Operational Resilience Act (DORA), applicable since January 2025, extends regulatory reach directly to the ICT providers serving financial entities, requiring demonstrable continuity and recovery capabilities across the supply chain. Financial market infrastructures operate under similarly demanding expectations. Under the CPMI-IOSCO Principles for Financial Market Infrastructures, business continuity arrangements should be designed to enable critical IT systems to resume operations within two hours following a disruptive event and allow settlement to be completed by the end of the day, even under extreme circumstances.
The direction is consistent across these frameworks: an institution's operational resilience is judged to include the resilience of its critical vendors. Outsourcing an operation does not outsource accountability for the risks associated with it.
Why Vendor Dependencies Can Amplify Disruption Risk
Three characteristics make technology providers a distinct resilience concern for central banks and financial institutions.
First, concentration. A technology vendor typically supports some of the most time-critical layers of an institution's operations. When a platform is deeply integrated and an alternative provider cannot be activated quickly, disruption can significantly limit the institution’s ability to process transactions or maintain normal service levels.
Second, opacity. An institution can directly test its internal recovery plans quarterly but have less visibility into whether a vendor's continuity plans are documented, regularly rehearsed, and governed, unless the vendor can evidence it.
Third, duration. Core financial infrastructure relationships span over many years. A vendor's resilience posture at the point of selection is a forecast of behavior across market shocks, regional instability, and organizational change that no one can predict at signing.
What Credible Resilience Evidence Looks Like
Because a vendor’s internal practices are difficult to observe from the outside, the evaluation becomes one of evidence. Assurances in a proposal are easy to write. Institutions should instead look for indicators that are structural and verifiable.
Independent certification of a business continuity management system. Third-party audit against an internationally recognized standard such as ISO 22301 replaces self-declaration with verification. It confirms that continuity policies exist, that recovery capabilities are exercised, that leadership accountability is defined, and that the system is reviewed and improved on a cycle, not assembled for a single tender.
Governance, not only plans. A continuity plan is a document; a business continuity management system is an operating discipline. Evaluators should establish who is accountable for continuity, how often recovery capabilities are tested, and how results feed back into ongoing improvement.
Transparency during assessment. A resilient vendor treats due-diligence questions on continuity as routine, and can produce scope statements, audit outcomes, and recovery objectives without improvisation. Reluctance here is itself an indicator of organizational maturity.
Track record through disruption. Recent years have supplied no shortage of stress events. How a vendor maintained services, communicated with clients and adapted its operations during significant disruptions or organizational changes is more instructive than any commitment about the future.
The Selection Decision, Reframed
Weighted this way, operational resilience stops being a compliance checkbox at the end of an RFP and becomes what it should be: a predictor of whether the institution's most critical services will remain dependable throughout the life of the contract. Two vendors with comparable functionality may not represent comparable risk if only one can evidence how it continues operating when conditions turn hostile.
For institutions carrying systemic or critical-service responsibilities, the conclusion is straightforward. The decisive question is not only “What can this vendor deliver?” but “What can this vendor deliver on its most difficult day?”
At ProgressSoft, this principle informs our continued investment in resilience and business continuity. ProgressSoft’s Business Continuity Management System has been independently certified to ISO 22301:2019, confirming that the management system within the certified scope conforms to the standard’s requirements. The certification forms part of the governance, operational discipline and continual improvement required to remain a dependable, long-term technology partner to financial institutions.