On September 9, 2026, Dolly Singh - Global Head of Third Party Oversight and CAO Chief Control Manager at JPMorganChase - published an essay on the firm's newsroom arguing that third-party risk management, as an industry practice, hasn't kept pace with how third-party relationships actually work today. It's a striking piece to see under a bank's own name, because the argument it makes is, point for point and as applied to open finance, the argument this blog has been building all year.
Her framing of the core problem is blunt: traditional due diligence is still largely a point-in-time exercise, even as the environment it's meant to assess keeps changing continuously underneath it. She names the pressures driving that gap directly - deeper technology integration, growing data volumes moving between organizations, concentration risk building up around a small number of dominant providers, and increasingly sophisticated, AI-enabled attackers. Her conclusion: oversight built for a slower era will keep falling behind the risks it exists to manage.
One key sentence: "TPRM needs to move at machine speed." That's not a call for faster paperwork. It's a statement that continuous, evidence-based assurance has to replace episodic review as the operating model - not as an efficiency upgrade, but because episodic review is structurally incapable of tracking risk that changes in real time.
Singh is careful, and rightly so, to separate two things that are easy to conflate: modernizing how oversight gets executed, and lowering the bar oversight is supposed to enforce. She's explicit that the goal is to keep the existing regulatory foundation intact while transforming execution - standardized, machine-readable evidence in place of manual document review; real-time monitoring and faster validation of controls in place of periodic snapshots; and effort concentrated on the relationships that carry the most risk rather than spread evenly regardless of actual exposure. She also flags a more specific idea: institutions should be able to see a clear, structured account of the software and AI components underlying a third party's service, not just a static compliance attestation - a level of transparency into what's actually running inside a vendor relationship that most current due diligence processes were never built to provide.
What makes the essay stand out is that Singh addresses all three parties in the chain, not just her own institution. Financial institutions, she argues, need to stop relying solely on point-in-time reviews and move to continuous, evidence-based assurance. Third parties need to make trusted evidence of their own controls readily available on an ongoing basis, not as an annual exercise. And policymakers need to support new approaches to validation and oversight - including direct regulatory attention to the small number of providers whose failure would carry systemic consequences.
That third point lands squarely alongside developments this blog has already covered this year including the Bank of England's Critical Third Parties regime bringing cloud and technology providers under direct supervision. Singh is describing the same shift from a different vantage point - not a regulator mandating oversight of a handful of designated providers, but a systemically important bank arguing that continuous oversight needs to become standard practice across the entire third-party relationship, not just the largest and most visible links in it.
It's one thing to argue, from outside the industry, that point-in-time accreditation isn't sufficient for how third-party relationships actually behave over time. It's another to have the person responsible for third-party oversight at one of the largest banks in the world make the identical argument, publicly, under her own name and her firm's. The specifics differ by context - a bank's vendor relationships aren't identical to an open finance network's aggregators and intermediaries - but the underlying structural problem is the same one: risk that evolves continuously cannot be managed by a control that only checks in once.
Modernizing third-party oversight, on Singh's own terms, doesn't mean fewer safeguards. It means building the infrastructure to keep the safeguards that already exist running continuously, at the pace the risk actually moves - which is exactly the argument for standing, independent monitoring rather than a periodic check, wherever in financial services that relationship happens to sit.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.
Learn more about the Invela Network.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.