Skip to content

Weekday Japan business intelligence for finance professionals.

Join the list
Tokyo Brief東 京 ブ リ ー フJapan's day, wrapped and delivered by morning.

Article

BIS and IOSCO Open Comment Window on FMI Cyber Resilience and Vendor Risk

Market participants have until December 1 to comment, in English, on two consultation papers from BIS's payments committee and IOSCO covering cyber resilience and third-party vendor dependency at financial market infrastructure, after Japan's FSA posted a notice pointing to the original documents.

Sep 14, 20262 min read
Abstract diagram of financial market infrastructure servers connected to smaller third-party vendor nodes, illustrating cyber resilience and vendor-dependency review.

Two of the bodies that write the rulebook for the plumbing of global finance have put material out for comment. On September 8, 2026, the Bank for International Settlements' Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) released two consultation papers on financial market infrastructure (FMI). Japan's Financial Services Agency posted a notice about the release on September 11, directing readers to the source documents on the BIS website rather than reproducing them itself.

The first paper is titled "Cyber resilience toolkit: practical considerations for FMIs." The second is a discussion paper called "FMI's reliance on third-party service providers: challenges and risks". The FSA notice gives only these titles and does not summarize their contents, so what counts as a "practical consideration," or which vendor arrangements the discussion paper flags as risky, is not public through this notice; readers who need the substance have to go to the BIS originals.

The FSA's own page carries a caveat that its machine-translated English content is "not necessarily correct," a reminder that the operational detail sits in the English-language originals from BIS and IOSCO, not in the Japanese notice itself.

The deadline matters more than the topic list at this stage. Comments are due by December 1, 2026, and must be submitted in English directly to the CPMI and IOSCO secretariats, not through the FSA or any national regulator. That is a roughly twelve-week window from publication, tight for firms that want board-level sign-off on a formal submission.

The FSA's role here is distribution, not authorship. The notice does not name any Japanese institution as a respondent, nor say whether the agency itself will file a comment. The task facing readers is straightforward: read both papers before December 1, and decide whether the standard-setters' framing of cyber resilience and vendor dependency matches what actually happens on the operations floor.