Two of the bodies that write the rulebook for the plumbing of global finance have put material out for comment. On September 8, 2026, the Bank for International Settlements' Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) released two consultation papers on financial market infrastructure (FMI). Japan's Financial Services Agency posted a notice about the release on September 11, directing readers to the source documents on the BIS website rather than reproducing them itself.
The first paper is titled "Cyber resilience toolkit: practical considerations for FMIs." The second is a discussion paper called "FMI's reliance on third-party service providers: challenges and risks". The FSA notice gives only these titles and does not summarize their contents, so what counts as a "practical consideration," or which vendor arrangements the discussion paper flags as risky, is not public through this notice; readers who need the substance have to go to the BIS originals.
The FSA's own page carries a caveat that its machine-translated English content is "not necessarily correct," a reminder that the operational detail sits in the English-language originals from BIS and IOSCO, not in the Japanese notice itself.
The deadline matters more than the topic list at this stage. Comments are due by December 1, 2026, and must be submitted in English directly to the CPMI and IOSCO secretariats, not through the FSA or any national regulator. That is a roughly twelve-week window from publication, tight for firms that want board-level sign-off on a formal submission.
The FSA's role here is distribution, not authorship. The notice does not name any Japanese institution as a respondent, nor say whether the agency itself will file a comment. The task facing readers is straightforward: read both papers before December 1, and decide whether the standard-setters' framing of cyber resilience and vendor dependency matches what actually happens on the operations floor.
