← Third-Party and Supply Chain Risk

CYB-25 · Cyber security

Policy administration system (PAS) risk — single-vendor dependency assessed with continuity controls

Almost all SA short-term insurance brokers depend on a single Policy Administration System. A ransomware attack on the PAS vendor — or a cloud outage — can render the broker operationally blind. The risk of this dependency must be explicitly assessed, with documented manual fallback procedures and SLA-backed recovery commitments from the vendor.

Medium priority

Trigger

When this rule fires

PAS vendor dependency not documented in risk register; no manual fallback procedures for PAS outage; PAS vendor has not provided cyber security assurance or SLA for recovery from a cyber incident

Applicability gate

Confirm the entity's role before treating this as a duty

This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.

  • Insurance Broker: Most independent non-life Category I brokers are not directly in JS2's defined scope. A broker may be directly in scope if it separately meets a listed category, and may face contract or oversight requirements from an in-scope institution. Third-party provisions impose duties on the in-scope financial institution. They do not themselves make every supplier or intermediary directly subject to JS2.
  • Uma Binder Holder: UMA or binder-holder status is not itself listed in JS2's definition. Direct scope depends on another listed capacity; insurer contracts and oversight may create evidence requirements. JS2 paragraph 3.3 concerns juristic persons structured under an insurer or designated insurance group; it is not a blanket rule for every independent UMA or intermediary.
  • Insurer: An insurer as defined in the Insurance Act is directly in scope of JS2 from 1 June 2025. Apply proportionality and distinguish the insurer's own duty from requirements it places on third parties.

Citation

Mapped source

This control maps to the public instruments below. The mapping does not establish entity applicability.

Section
Joint Standard 1 of 2023 (IT continuity management) / Joint Standard 2 of 2024 — paragraph 7.4 (response and recovery)
Legislation
  • Joint Standard 1 of 2023
  • Joint Standard 2 of 2024

Remediation

How to close the gap

Document the PAS vendor as a critical single point of dependency. Obtain the vendor's Business Continuity and Disaster Recovery plan. Define manual fallback procedures (paper-based policy documentation) for 48-hour outage scenario. Review vendor's cyber insurance status.

Evidence required

Evidence to prepare if this control applies

  • PAS vendor in critical vendor register
  • Vendor BCP/DR plan or summary
  • Manual fallback procedure documentation
  • PAS vendor SLA with cyber incident recovery terms