Fundamental Elements
To help address cyber risks, the G7 Fundamental Elements of Cybersecurity for the Financial
Sector were issued in October 2016, and the G7 Fundamental Elements for Effective Assessment
of Cybersecurity in the Financial Sector were issued in October 2017. To further support the
development of third-party cyber risk management in the financial sector, the G7 issued the
Fundamental Elements for Third Party Cyber Risk Management in the Financial Sector in 2018.
To address industry developments since 2018, the G7 has revised the 2018 Fundamental Elements
so as to focus not only on the management of third-party relationships but also on ICT supply
chain management. The updated Fundamental Elements stress the importance of extensive
information sharing and transparency to cope with an ever-changing threat landscape. To draw
attention to the increasingly important role of third parties in the financial sector, a new
fundamental element (Element 7) has been added.
Entities should tailor the Fundamental Elements, as appropriate, to their specific risk profiles,
operational and threat landscapes, roles in the sector, and legal and regulatory frameworks. The
elements are non-binding and do not invalidate existing frameworks or prevent their continuous
adaptation. The following Fundamental Elements consider the Third-Party Cyber Risk
Management Life Cycle within an individual entity, the role of a third party to the financial sector,
as well as system-wide monitoring of cyber risk. Moreover, these Fundamental Elements consider
the Third-Party Cyber Risk Management within the entire ICT supply chain of an individual entity.
Entities and third parties can use these Fundamental Elements as part of their cyber risk
management toolkit. In doing so, entities should apply a proportionate approach that takes into
account the size, nature, scope, complexity and potential systemic significance of the third-party
relationship.
Authorities within and across jurisdictions can use the Fundamental Elements to inform their
public policy, regulatory, and supervisory efforts to address third-party cyber risks.
Third-Party Cyber Risk Management Life Cycle
Element 1: Governance
Entities’ governing bodies are responsible and accountable for effective oversight and
implementation of third-party cyber risk management.
Entities’ governing bodies, such as boards of directors and senior management, are ultimately
responsible and accountable for overseeing and implementing the management of the entities’
cyber risks, including those posed by its third-party relationships. This oversight and
implementation includes: a documented strategy addressing the reliance on third parties; thirdparty and cyber risk policies; setting a risk tolerance for third-party relationships; and clear roles,
responsibilities, and accountabilities for third-party cyber risk management integrated into the
enterprise risk control functions, managed in proportion to the level of risk and criticality of a given
activity. It also includes appropriate communication and escalation processes as a normal course
of business at all levels within the entity, and between the entity, the third party and relevant
authorities.
TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction.
2