MAS.TRM.2021.Sec6.4.2.p21.OBL1
Software Application Development and ManagementA well-defined vetting process should be implemented for assessing third parties’ suitability in connecting to the FI via APIs, as well as governing third party API access.
A well-defined vetting process should be implemented to assess whether third parties are suitable to connect to the FI via APIs and to govern their API access.
Deontic
recommendation
Type
Process
Strength
Recommended
Frequency
Ongoing
Status
In Force
Sanction
supervisory
Document the vetting process applied to third parties seeking API connectivity.
Done WhenA written vetting process exists, stating the assessment steps, who performs them and who decides the outcome, and it is dated and approved.
EvidenceThird party API vetting process document
Run the vetting process for each third party before it is connected via an API.
Done WhenFor each third party with API connectivity, a completed vetting record exists and is dated before the connection was enabled.
EvidenceCompleted third party vetting record
Maintain the controls that govern third party API access after onboarding.
Done WhenA record exists showing, for each third party, which APIs it is authorised to access and the approval on which that access rests.
EvidenceThird party API access record
Why This Exists
An API connection hands a counterparty a live route into the FI's systems. Judging counterparties case by case without a defined process gives inconsistent decisions and lets weak parties through on the strength of a commercial relationship.
Relationship
This is the first of two sentences in 6.4.2, creating the process, while the second sentence sets what the criteria must consider.
Interpretation
A guideline "should", so a supervisory expectation. Two jobs sit in one sentence. The process assesses suitability, and it also governs third party API access, so this is not only an onboarding gate. "Well-defined" points at a documented and repeatable process rather than individual judgement. The criteria the process must weigh come from the second sentence of the same paragraph. 6.4.3 adds a separate risk assessment before connection, so vetting the party does not discharge the assessment of the connection itself.
Watchouts
The words "as well as governing third party API access" are easy to skim past. They turn a point-in-time due diligence exercise into a continuing control over live connections.
Generated regulatory intelligence, traceable to the citation below. The verbatim source text remains the authority you cite.
MAS TRM, Section 6.4.2, p. 21 (2021)
Consequence. Non-adherence may attract MAS supervisory action; the TRM Guidelines set out the standards MAS expects financial institutions to meet.