VM-04 Third-Party / Vendor Management

Outsourcing Register & MAS Compliance

Material outsourcing meets MAS expectations.

Domain
Third-Party / Vendor Management
Control type
Preventive/Detective
Automated / manual
Manual
Frequency
Per arrangement
Framework reference
MAS Outsourcing

What good looks like

Outsourcing recorded in a register with audit rights, sub-contracting controls and MAS notification.

Risk if it fails

Non-compliance with MAS outsourcing.

How Tess tests it

3 tests — each concludes only on cited evidence.

Outsourcing register maintained

Design
Procedure
Inspect the register.
Expected
Exists and complete.
Sample
1 (design inspection)
Evidence
Outsourcing register, contracts, MAS notifications.

Contracts include audit & sub-contracting controls

Operating
Procedure
Sample contracts.
Expected
Clauses present.
Sample
Judgmental, by population (e.g. 10–25)
Evidence
Outsourcing register, contracts, MAS notifications.

MAS notification made where required

Operating
Procedure
Inspect notifications.
Expected
Compliant.
Sample
Judgmental, by population (e.g. 10–25)
Evidence
Outsourcing register, contracts, MAS notifications.

Evidence Tess looks for

Outsourcing register, contracts, MAS notifications.

More in Third-Party / Vendor Management

Want Tess to test VM-04 against your evidence?

Book a demo