Q&A: Financial services resilience: technology, third parties and systemic risk
November 2026 | SPECIAL REPORT: FINANCIAL SERVICES
Financier Worldwide Magazine
FW discusses financial services resilience through the lens of technology, third parties and systemic risk, with Allen Applbaum, Michael Costa and Luke Tenery at StoneTurn.
FW: In what ways has the financial services resilience landscape changed in recent years, particularly as technology dependencies, third-party relationships and systemic risks have become more prominent?
Tenery: Resilience previously meant fairly simplistic contingencies covering redundant data centres and disaster recovery plans. Today, it additionally means understanding concentration risk on how deeply embedded and integrated cloud providers, data vendors and third party fintech platforms are in a financial institution’s (FI’s) core operations. A single outage at a shared infrastructure provider can now ripple across dozens of FIs simultaneously, turning what was once an isolated IT issue into a sector-wide event. Regulators have taken notice: frameworks like the Digital Operational Resilience Act (DORA) in the European Union and heightened Federal Financial Institutions Examination Council and Office of the Comptroller of the Currency expectations in the US now explicitly require FIs to map and stress test these dependencies. Operational resilience has evolved from a single dimension concern to a multidimensional set of calculations. It is going to be further complicated as artificial intelligence (AI)-enabled functions and data centre compute shortages further abstract resilience and processing supply.
Applbaum: Regulators are increasingly looking at resilience gaps – whether in anti-money laundering (AML) systems, transaction monitoring platforms or outsourced compliance functions – as core safety and soundness issues, not mere ‘technology glitches’. FIs under consent orders or independent consultancies are now expected to show that their third party and technology risk frameworks are just as robust as their internal controls because a failure anywhere in that chain can potentially undermine an entire compliance programme.
“Tabletop exercises should function at both the leadership and tactical levels, ideally simulating considerations like a disruption at a key vendor or cloud provider.”
FW: To what extent are operational disruptions, technology failures and cyber incidents now viewed as systemic threats on a par with more traditional financial risks?
Tenery: These issues are increasingly considered a material concern, with all public global banks mentioning them as part of their top risks in their public filings alongside issues like AML, regulatory issues and liquidity concerns. Regulators, rating agencies and boards now ask cyber incident, AI and digital asset risk management questions. Regarding cyber incidents, they are asking how quickly the organisation can detect it, contain it and recover critical functions. Government and non-governmental organisations have flagged operational and cyber risk as potential sources of systemic concerns, not just idiosyncratic institutional failures. What has changed is the recognition that a technology failure at a critical service provider does not stay contained to one firm; it can disrupt customer operations across an entire market segment.
FW: How concerned should FIs be about growing concentration risk arising from reliance on a relatively small number of cloud, data and infrastructure providers?
Tenery: This must be top of mind, although the top tiers of global FIs have been collaborating closely with hyperscalers for several years. A handful of hyperscale cloud providers and core data vendors now likely underpin a significant share of the sector’s infrastructure, meaning an outage, misconfiguration or incident can have an impact across one or more institutions. This concentration also creates a visibility gap: FIs often have limited insight into a provider’s own subcontractors, patching cadence or incident history, even though their own resilience depends on it. The answer is not necessarily to abandon these providers, given their scale often delivers better security than most institutions could build alone. Instead, FIs should actively map dependencies, negotiate meaningful risk management into contracts and maintain contingency plans for a provider-level disruption.
Applbaum: Regulators are watching closely. The New York State Department of Financial Services and other state and federal regulators have signalled that concentration in critical vendors is itself a focus of examinations, and FIs that cannot demonstrate a credible contingency plan for a key provider’s failure may face heightened scrutiny, regardless of how strong their internal controls otherwise are.
“To sensibly deploy AI and automations, organisations should begin by weighing risk and capabilities.”
FW: What are the biggest challenges organisations face in identifying and managing risks across complex outsourcing arrangements, critical vendors and fourth-party dependencies?
Applbaum: The biggest challenge here is transparency and visibility beyond the first tier. FIs can generally assess and monitor direct vendors, but fourth- and fifth-party dependencies are often invisible until something goes wrong. We have seen organisations with mature-looking vendor management programmes that are still not able to answer basic questions about who their critical vendors rely on, or what controls those subcontractors have in place. Compounding this, many outsourcing agreements were negotiated years ago without meaningful audit rights, incident notification requirements or exit provisions, leaving FIs with limited leverage when a downstream problem surfaces. Building a robust programme that is able to map dependencies several layers deep, and periodically validate vendor representations rather than merely accepting them at face value, remains one of the most challenging and under-resourced parts of a resilience programme.
Tenery: On the cyber side, the challenge compounds further: most FIs have had to further scale their third party risk management capabilities to evaluate their vendors’ security posture. Historically, they relied upon attestations and point-in-time audits. Now they have more direct and indirect intelligence gathering related to their vendors’ systems and existential threats.
FW: As cyber threats become more sophisticated and interconnected, what practical steps can FIs take to strengthen resilience against disruptions that could affect multiple organisations simultaneously?
Tenery: FIs should start by mapping which critical functions and assets depend on external infrastructure, then build and test health-monitoring controls. Furthermore, they need to plan and test for impacts against assets through resiliency activities that include rehearsals of the operational continuity and security response plans. Tabletop exercises should function at both the leadership and tactical levels, ideally simulating considerations like a disruption at a key vendor or cloud provider. FIs should also work with their legal teams to push for stronger contractual rights that may include real-time incident notification, audit or independent assessment access, and clearly defined recovery-time commitments from critical providers.
FW: How can firms balance the opportunities presented by AI and automation with the need for effective governance, controls and operational resilience?
Costa: The firms striking this balance are not treating AI governance as a retroactive measure; they are developing purpose-built controls around each specific use case and tool. To sensibly deploy AI and automations, organisations should begin by weighing risk and capabilities. Where not to deploy AI should be a common question. A well-established framework, such as that of the Committee of Sponsoring Organizations of the Treadway Commission, gives compliance and risk teams a familiar structure to assess the design, testing and monitoring of AI tools before deployment. Applied thoughtfully, AI and advanced analytics can process volumes of data – transaction monitoring, employee surveys and compliance documentation – that would take teams of humans weeks to review, surfacing patterns and risks far faster, and assessing data by a single, consistent evaluator. But resilience requires clear ownership – human ownership – of the automation. Who owns the AI automation? Who monitors its ongoing performance? Who is accountable for relying on the outputs? When a human makes a mistake, we have an organisational chart that shows responsibility. When an AI makes a mistake, an organisational chart should be no less relevant.
“FIs that cannot demonstrate a credible contingency plan for a key provider’s failure may face heightened scrutiny, regardless of how strong their internal controls otherwise are.”
FW: Which emerging risks, technologies or regulatory developments are most likely to shape the future direction of financial services resilience over the next three to five years?
Costa: AI agents and agentified automations will be the defining force – both increasing capabilities and creating new risk vectors. FIs will increasingly rely on AI judgements and difficult to trace reasoning behind automated decisions. Implicit guardrails on technology or processes are no longer effective. Uncodified norms or procedures will have little value to AI systems. I predict that compliance departments will spend a lot of time and resources over the next three to five years making policies machine readable, scoping policies to individual actions and decisions, and generally rethinking how these systems are best applied.
Tenery: On the cyber and infrastructure side, expect continued regulatory convergence around operational resilience – following the lead of frameworks like DORA – along with growing scrutiny of concentration risk in cloud and critical technology providers. AI-driven threat actors will also raise the sophistication and speed of attacks, pushing FIs toward more automated, real-time detection, mitigation and response capabilities. Potential growth in further integration of digital assets within the financial system presents additional challenges and security and resiliency concerns for FIs.
Applbaum: From a compliance and enforcement standpoint, I expect regulators to increasingly hold FIs accountable for the resilience and integrity of outsourced and technology-driven compliance functions, particularly AML and fraud monitoring systems, treating a vendor’s failure as the FI’s own regulatory failure.
Allen D. Applbaum, a partner with StoneTurn and former federal prosecutor, has more than three decades of experience in investigations, asset tracing and recovery, litigation, business intelligence, due diligence, corporate governance, monitoring and compliance. In connection with his management of high-profile investigations, he draws on his public and private sector experience to integrate investigative skills with technology, data analytics, and financial expertise to provide clients with seamless approaches to critical problems. He can be contacted on +1 (212) 430 3449 or by email: aapplbaum@stoneturn.com.
Michael Costa, a partner in AI advisory and transformation, leverages data analytics and data science, investigations, complex litigation and compliance matters. He applies artificial intelligence and advanced analytics to help clients uncover insights, assess risk and drive informed decision making in complex matters. He has provided data analytics expertise to clients on matters involving compliance and remediation, fraud investigations, complex litigation and monitorships. He can be contacted on +1 (312) 775 1212 or by email: mcosta@stoneturn.com.
Luke Tenery brings over 20 years of experience helping leading organisations mitigate complex cyber security, data privacy and digital risks. He applies expertise in cyber investigations, threat intelligence, incident response and information risk management to assist clients – from prevention to detection, mitigation through to remediation and transformation. Mr Tenery specialises in situational cyber risks and assists public companies and their boards in addressing digital risks and remediation of complex cyber incidents. He can be contacted on +1 (312) 775 1210 or by email: ltenery@stoneturn.com.
© Financier Worldwide