CHILE Trends and Developments Contributed by: Carolina Cabrera, LawTech
A notable trend among organisations undertaking complex transformation initiatives is the recognition that technology projects often involve broader gov - ernance considerations. Successful programmes increasingly appear to depend upon the ability to inte - grate technology, regulation, risk management and business strategy within a common decision-making framework. This convergence is also contributing to growing demand for professionals capable of operating across traditionally separate disciplines. Organisations are placing greater emphasis on multidisciplinary teams that can understand technology architecture, regula - tory requirements, cybersecurity risks and commercial objectives simultaneously. Why Third-Party Risk Management Has Become a Strategic Priority One of the most significant regulatory trends affecting technology projects is the growing emphasis on third- party risk management. Organisations increasingly rely on external providers for critical functions. Cloud providers host essential infrastructure. Software vendors deliver business-crit - ical applications. Managed service providers support operational processes. Specialist technology firms implement and maintain complex digital solutions. This dependence creates efficiencies and enables innovation. However, it also introduces new forms of risk. A security incident affecting a provider may disrupt business operations. A data protection failure may expose the client to regulatory scrutiny. Deficien - cies in outsourced technology may also create opera - tional, legal and reputational consequences. Regulators are increasingly responding to these risks by imposing greater expectations on organisa - tions that outsource critical activities. The underlying principle is straightforward: responsibility for regula - tory compliance cannot be entirely delegated simply because a service is performed by an external pro - vider. Market practice suggests that vendor selection pro - cesses have become considerably more sophisticated
in recent years. Organisations undertaking large-scale cloud migration, enterprise software implementation and managed services projects are increasingly seek - ing evidence of cybersecurity maturity, governance capabilities and compliance frameworks as part of procurement and due diligence exercises. This trend appears particularly visible in regulated industries and in organisations operating critical digital infrastructure, where regulatory scrutiny and opera - tional resilience requirements continue to increase. The financial services sector provides a particularly clear example. Supervisory expectations issued by the CMF have contributed to raising standards regard - ing outsourcing governance, technology risk manage - ment and oversight of critical service providers. As a result, financial institutions are increasingly seeking contractual frameworks that provide greater transpar - ency, audit rights, incident reporting mechanisms and operational resilience commitments from technology providers. The enactment of the Fintech Law (Law No 21,521) has further contributed to this evolution. As new regu - lated participants enter the financial ecosystem and increasingly rely on digital platforms, cloud services and third-party technology providers, governance and risk management considerations are becoming more relevant in the design and operation of technology- enabled financial services. Consequently, organisations are expected to exer - cise more active oversight throughout the supplier life cycle. This often includes: • conducting due diligence before engaging provid - ers; • assessing cybersecurity capabilities and govern - ance practices; • evaluating operational resilience and business con - tinuity arrangements; • understanding subcontracting structures; and • monitoring compliance and performance on an ongoing basis. The result is a relationship that is becoming increas - ingly collaborative. Effective risk management
31 CHAMBERS.COM
Powered by FlippingBook